T09 · Insecure Skill Coding Practices
- Location
search-stop.sh:7- Finding
User-Controlled grep Option Injection in Stop Search
- Content
View full analysis
Vulnerability Details
File Location:
search-stop.sh, lines 7–18
Vulnerability Type: User-controlled command option injection
Risk Level: MediumVulnerable Code
bash QUERY="${1:-}" if [ -z "$QUERY" ]; then echo "Usage: $0 <stop-name>" echo "Example: $0 stephansplatz" exit 1 fi echo "Searching for stops matching: $QUERY" echo "---" echo "StopID;DIVA;StopText;Municipality;Longitude;Latitude" curl -s "https://www.wienerlinien.at/ogd_realtime/doku/ogd/wienerlinien-ogd-haltepunkte.csv" | grep -i "$QUERY" | head -20Technical Analysis
The stop name is passed to
grepwithout an option terminator. Shell quoting prevents shell metacharacters inQUERYfrom being evaluated as shell syntax, but it does not preventgrepfrom treating a value beginning with-as a command-line option.For example, an argument in the form
-f/path/to/filecan directgrepto load patterns from a local file. The input is also interpreted as a regular expression even though the documented operation is a stop-name search. This permits unintended matching behavior and potentially expensive regular-expression processing.This is argument injection into
grep, not arbitrary shell-command injection: the vulnerable code does not useeval, an unquoted shell expansion, or a nested shell.Attack Path
- An attacker or untrusted caller supplies a crafted stop-name argument beginning with a valid
grepoption. - The agent or user invokes
search-stop.shwith that argument. - The script expands the argument as
grep -i "$QUERY". grepinterprets the crafted value as an option rather than a search pattern.- Depending on the option,
grepmay read an attacker-selected local file as a pattern source, alter matching behavior, emit errors, or consume additional resources. - The resulting patterns are applied to the public Wiener Linien CSV stream, and matching CSV lines may be ...[truncated 608 chars]
- An attacker or untrusted caller supplies a crafted stop-name argument beginning with a valid
- Remediation
View remediation
Remediation Suggestions
Terminate option parsing and use fixed-string matching because the documented input is a literal stop name:
bash curl -fsS \ "https://www.wienerlinien.at/ogd_realtime/doku/ogd/wienerlinien-ogd-haltepunkte.csv" | grep -iF -- "$QUERY" | head -20Security hardening should include:
- Use
--before the query so values beginning with-cannot be parsed as options. - Use
-Fto disable regular-expression interpretation and perform a literal stop-name search. - Use
curl -fSso HTTP failures are reported rather than silently passed to the parser. - Consider adding a reasonable query-length limit to reduce resource-abuse risk.
- Add regression tests for inputs such as
-f/etc/passwd,--help, regex metacharacters, spaces, and non-ASCII stop names.
- Use
