T09 · Insecure Skill Coding Practices
- Location
scripts/query_template_generator.py:231- Finding
Unvalidated Structural Query Interpolation Enables Cypher and SPARQL Injection
- Content
View full analysis
(b:{target}) RETURN a, b LIMIT $limit""" ``` ```python return QueryTemplate( name=f"sparql_{source}_{rel_type}", query=f"""PREFIX ex: SELECT ?source ?target WHERE {{ ?source ex:{rel_type} ?target . }} LIMIT $limit""", language=language, parameters=[Parameter("limit", "integer", "Result limit", default_value=100)] ) ``` ```python query = f"""MATCH path = (start:{start})-[*1..{max_depth}]-(end:{end}) RETURN path, LENGTH(path) as hops LIMIT $limit""" ``` ```python return QueryTemplate( name=f"sparql_paths_{start}_{end}", query=f"""PREFIX ex: SELECT ?path WHERE {{ ?start a ex:{start} ; ex:connects* ?end . ?end a ex:{end} . }} LIMIT $limit""", language=language ) ``` ```python query = f"""MATCH (s:{source})-[:{rel}]->(t:{target}) RETURN t.{group_by}, COUNT(s) as count GROUP BY t.{group_by} ORDER BY count DESC LIMIT $limit""" ``` ```python return QueryTemplate( name=f"sparql_aggregate_{source}", query=f"""PREFIX ex: SELECT ?category (COUNT(?item) AS ?count) WHERE {{ ?item a ex:{source} ; ex:{rel} ?category . }} GROUP BY ?category ORDER BY DESC(?count) LIMIT $limit""", language=language ) ``` ```python query = f"""MATCH (n:{label}) WHERE n.{property_name} {operator} $value RETURN n LIMIT $limit""" ``` ```python return QueryTemplate( name=f"sparql_filter_{label}", query=f"""PREFIX ex: SELECT ?en ...[truncated 3907 chars]- Remediation
View remediation
", "gt": ">", "gte": ">=", "lt": "<", "lte": "<=", } ``` - Never insert an arbitrary operator string supplied by a caller. 3. **Constrain traversal depth** - Require an actual integer rather than accepting arbitrary string formatting. - Reject booleans and non-integer values. - Apply conservative bounds, for example: ```python if not isinstance(max_depth, int) or isinstance(max_depth, bool): raise TypeError("max_depth must be an integer") if not 1 <= max_depth <= 4: raise ValueError("max_depth must be between 1 and 4") ``` 4. **Use safe identifier quoting where supported** - Apply the target database driver's official identifier-escaping mechanism after validation. - Do not treat quoting alone as sufficient; schema allowlisting remains preferable. - For SPARQL, construct IRIs through an RDF/SPARQL library rather than concatenating fragments into query text. 5. **Separate trusted schema configuration from user data** - Accept user-provided values only through database parameters. - Resolve user-facing choices to internally defined labels, relationships, predicates, and operators. - Avoid exposing raw query-structure arguments in public API endpoints. 6. **Strengthen template validation** - Extend ...[truncated 1039 chars]
