T09 · Insecure Skill Coding Practices
- Location
crypto-monitor.sh:125- Finding
API-Controlled Python Code Injection
- Content
View full analysis
/dev/null || echo "$gold") local prev_silver=$(echo "$prev" | python3 -c "import sys,json; print(json.load(sys.stdin).get('silver', $silver))" 2>/dev/null || echo "$silver") ``` The interpolated values originate from external API responses: ```bash gold=$(echo "$gold_resp" | python3 -c "import sys,json; print(json.load(sys.stdin).get('price', 2650))" 2>/dev/null || echo "2650") ``` ### Technical Analysis The `$gold` and `$silver` shell variables are inserted directly into the source code passed to `python3 -c`. The values are not validated as finite numeric values before interpolation. In particular, `$gold` can originate from the GoldAPI.io or Yahoo Finance response. JSON parsing alone does not enforce a numeric type: if an API returns a JSON string, Python's `print()` emits that string, after which the shell inserts it into a subsequent Python program. The default argument supplied to `dict.get()` is evaluated before the method is called, even when the requested key already exists. Consequently, an injected Python expression in `$gold` or `$silver` is evaluated whenever these lines execute. ### Attack Path 1. An attacker compromises, controls, or successfully spoofs one of the external market-data responses. 2. The response contains a syntactically valid JSON value whose `price` field is a string containing a Python expression, such as an expression invoking `os.system()`. 3. The script parses and assigns that string to `$gold`. 4. A pre-existing `/tmp/crypto-monitor/metals_history.json` file causes the history-processing branch to execute. 5. The string is interpolated into the `python3 -c` program at line 125. 6. Pyth ...[truncated 747 chars]- Remediation
View remediation
