T03 · Remote Payload Retrieval and Execution
- Location
references/setup.md:10- Finding
Unverified Remote Installer Is Piped Directly Into a Shell
- Content
View full analysis
Vulnerability Details
File Location:
references/setup.md, line 10
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighComplete Code Snippet
bash # Any platform curl -sSL https://github.com/longbridge/longbridge-terminal/raw/main/install | shTechnical Analysis
The installation command retrieves a shell script from an external URL and sends it directly to
sh. The URL tracks the mutablemainbranch rather than an immutable release or commit. Consequently, the code executed at installation time can differ from the code that was available when this Skill was audited.No checksum, cryptographic signature, fixed version, or review step validates the downloaded content. The use of
curl -sSLalso suppresses normal progress and follows redirects, while the pipeline immediately executes the resulting response. Although the URL belongs to the stated Longbridge GitHub organization, trust in the organization does not eliminate risks from repository compromise, maintainer-account compromise, malicious upstream changes, redirected responses, or distribution infrastructure compromise.Installing the CLI is consistent with the Skill's declared functionality, but executing mutable remote content without verification exceeds the minimum mechanism necessary to perform that installation. A signed package-manager release or a separately downloaded and verified artifact would provide the required functionality with less risk.
Attack Path
- An attacker compromises the upstream repository, a maintainer account, or infrastructure involved in delivering the installer.
- The attacker modifies the installer on the
mainbranch or causes the URL to return attacker-controlled shell commands. - A user or AI agent follows the documented installation command.
curldownloads the current response and pipes it directly tosh.- The shell executes the attacker-controlled commands without local inspection or integr ...[truncated 864 chars]
- Remediation
View remediation
Remediation Suggestions
- Prefer the documented Homebrew installation path or another package manager that supports signed, versioned releases.
- Do not pipe network responses directly into a shell.
- Pin downloads to an immutable release version or commit rather than
main. - Download the installer or binary to a local file first.
- Verify a publisher-provided cryptographic signature or SHA-256 checksum obtained through a trusted channel.
- Allow the user to inspect the script before execution and require explicit confirmation.
- Avoid administrator privileges unless the selected destination strictly requires them; prefer a user-owned binary directory where practical.
- Document the files and directories the installer changes and provide an uninstall procedure.
A safer pattern is:
bash curl -fL --proto '=https' --tlsv1.2 \ -o longbridge-install.sh \ 'https://raw.githubusercontent.com/longbridge/longbridge-terminal/IMMUTABLE_COMMIT/install' echo 'EXPECTED_SHA256 longbridge-install.sh' | sha256sum -c - less longbridge-install.sh sh longbridge-install.shThe commit and checksum must come from a verified official release; placeholders must not be used as actual values.
