T09 · Insecure Skill Coding Practices
- Location
references/windows-equivalents.md:147- Finding
PowerShell Command Injection Through Unvalidated DAYS in ftdata.bat
- Content
View full analysis
Vulnerability Details
File Location:
references/windows-equivalents.md, lines 147–166
Vulnerability Type: PowerShell command injection through unsafe batch-variable interpolation
Risk Level: HighVulnerable Code
batch REM Parameters: ftdata.bat PAIR DAYS TIMEFRAME [--erase] set PAIR=%~1 if "%PAIR%"=="" set PAIR=BTC/USDT set DAYS=%~2 if "%DAYS%"=="" set DAYS=30 set TIMEFRAME=%~3 if "%TIMEFRAME%"=="" set TIMEFRAME=5m set ERASE=%~4 REM NOTE: Windows cmd/PowerShell lack bash regex. Validate in PowerShell before calling batch, REM or add whitelist checks: verify PAIR contains only alphanumeric/slash, REM TIMEFRAME matches ^\d+(m|h|d)$, and ERASE is empty or "--erase". REM To prevent injection, always quote variables: "%PAIR%", "%TIMEFRAME%", etc. REM Calculate start date (DAYS ago) for /f %%A in ('powershell -Command "(Get-Date).AddDays(-!DAYS!).ToString('yyyyMMdd')"') do ( set START_DATE=%%A )Technical Analysis
The second command-line argument is assigned to
DAYSwithout validating that it is a bounded integer. Because delayed expansion is enabled,!DAYS!is expanded directly into the source text passed toPowerShell -Command.The variable is therefore interpreted as PowerShell syntax rather than as an isolated data value. An attacker who can influence the second argument can provide PowerShell metacharacters or expression syntax that changes the intended
AddDaysexpression and introduces additional commands.The comments recommend validating other parameters and quoting Docker arguments, but they neither validate
DAYSnor protect the PowerShell source construction. Quoting the overall-Commandargument does not make interpolation safe because the resulting content is deliberately parsed by PowerShell.Attack Path
- A user copies the documented
ftdata.batimplementation and invokes it in a Command Prompt session. - An attacker, untrusted wrapper ...[truncated 950 chars]
- A user copies the documented
- Remediation
View remediation
Remediation Suggestions
- Validate
DAYSbefore it reaches PowerShell and reject any value containing non-decimal characters. - Apply a reasonable positive range, such as 1 through an explicitly documented maximum, to prevent abusive or accidental date ranges.
- Avoid constructing PowerShell source code by concatenating user input. Pass the value as a separately validated argument and convert it with a strict integer parser.
- Terminate execution with a nonzero exit code when validation fails.
- Add security tests covering shell metacharacters, parentheses, quotes, whitespace, negative values, excessively large values, and empty input.
A minimum batch-side validation should ensure the value contains digits only before invocation. A safer design is to perform strict conversion in a dedicated PowerShell script using an integer-typed parameter and invoke that script with an argument rather than embedding the value in
-Command.- Validate
