T09 · Insecure Skill Coding Practices
- Location
run_gold_price.sh:4- Finding
Unchecked Directory Change Can Cause Execution of an Unintended Local Script
- Content
View full analysis
Vulnerability Details
File Location:
run_gold_price.sh, lines 4-12
Vulnerability Type: Untrusted relative-path execution after an unchecked directory-change failure
Risk Level: MediumVulnerable Code
bash SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd)" PLAYWRIGHT_DIR="$SCRIPT_DIR/../playwright-scraper-skill" echo "=== 💰 金价自动汇报 ===" echo "时间: $(date '+%Y-%m-%d %H:%M')" echo "" # 使用playwright获取金价 cd "$PLAYWRIGHT_DIR" OUTPUT=$(node scripts/playwright-simple.js "http://www.huangjinjiage.cn/jinrijinjia.html" 2>&1)Technical Analysis
The script changes to the expected sibling dependency directory but does not check whether
cd "$PLAYWRIGHT_DIR"succeeds. It also does not enable immediate termination on command failures. If the directory is missing or inaccessible, execution continues in the process's previous working directory.The subsequent Node.js command uses the relative path
scripts/playwright-simple.js. Consequently, after a failed directory change, Node.js resolves that path beneath the caller-controlled working directory rather than the intendedplaywright-scraper-skilldirectory.The audited project does not contain the referenced sibling dependency, making a failed directory change a realistic deployment condition. Exploitation still requires an attacker to influence the launch directory and place a file at the expected relative path.
Attack Path
- The expected sibling directory,
../playwright-scraper-skill, is absent, inaccessible, or renamed. - An attacker creates a malicious file at
scripts/playwright-simple.jsbeneath a directory they control. - The victim launches
run_gold_price.shwhile that attacker-controlled directory is the current working directory. - The
cd "$PLAYWRIGHT_DIR"command fails, but the shell continues execution. - Node.js resolves
scripts/playwright-simple.jsfrom the unchanged working directory. - The atta ...[truncated 498 chars]
- The expected sibling directory,
- Remediation
View remediation
Remediation Suggestions
-
Enable strict shell error handling near the beginning of the script:
bash set -euo pipefail -
Explicitly verify that the dependency directory and target script exist before execution:
bash PLAYWRIGHT_SCRIPT="$SCRIPT_DIR/../playwright-scraper-skill/scripts/playwright-simple.js" if [[ ! -f "$PLAYWRIGHT_SCRIPT" ]]; then printf 'Required scraper script was not found: %s\n' "$PLAYWRIGHT_SCRIPT" >&2 exit 1 fi -
Invoke the validated script by its absolute path instead of relying on the current working directory:
bash OUTPUT=$(node "$PLAYWRIGHT_SCRIPT" \ "https://www.huangjinjiage.cn/jinrijinjia.html" 2>&1) -
If changing directories remains necessary, fail explicitly when it is unsuccessful:
bash cd "$PLAYWRIGHT_DIR" || { printf 'Cannot access dependency directory: %s\n' "$PLAYWRIGHT_DIR" >&2 exit 1 } -
Deploy the sibling scraper as a pinned, integrity-verified dependency and restrict write access to its installation directory.
-
