T07 · Tool Hijacking and Spoofing
- Location
scripts/common.sh:88- Finding
Environment-Controlled Backend Loading Allows Policy Bypass and Arbitrary Shell Sourcing
- Content
View full analysis
- Remediation
View remediation
&2 exit 1 ;; esac ``` Additional hardening should include: 1. Remove operational deprecated backends from the distributed package. 2. Reject values containing `/`, `\`, `..`, control characters, or whitespace. 3. If multiple backends are supported later, map fixed identifiers to fixed canonical paths instead of interpolating identifiers into paths. 4. Resolve and verify the canonical path before sourcing it. 5. Require the canonical path to be a direct child of the backend directory. 6. Consider running third-party backend adapters in isolated subprocesses rather than sourcing them into the main shell. 7. Add regression tests for `_deprecated/codex`, `../`, absolute paths, and encoded or repeated path separators. ]]>
