T09 · Insecure Skill Coding Practices
- Location
scripts/install-browser.sh:120- Finding
Command Injection Through Unsafely Generated Chrome Wrapper
- Content
View full analysis
Creating wrapper script..." cat > "$WRAPPER" << WEOF #!/bin/bash export LD_LIBRARY_PATH=${LIBS_DIR}/lib\${LD_LIBRARY_PATH:+:\$LD_LIBRARY_PATH} export FONTCONFIG_FILE=${FC_CONF} exec ${CHROME_BIN} "\$@" WEOF chmod +x "$WRAPPER" echo "==> Verifying Chrome..." VERSION=$("$WRAPPER" --version 2>/dev/null || echo "FAILED") echo " $VERSION" ``` ### Technical Analysis The `--chrome-dir` and `--libs-dir` arguments are accepted without validation and assigned to `CHROME_DIR` and `LIBS_DIR`. These values are subsequently expanded into an unquoted heredoc used to generate an executable shell script. Because the heredoc delimiter is unquoted, parameter expansion occurs while the wrapper is generated. More importantly, the expanded path values are inserted directly into shell source code without shell-safe serialization or runtime quoting. A path containing whitespace, command separators, shell operators, command substitutions, or newline characters can therefore change the syntax and behavior of the generated wrapper. The installer grants execute permission to the wrapper and immediately runs it for version verification. Consequently, injected commands can execute during installation rather than requiring a later browser launch. The malicious code also remains embedded in the generated wrapper and may execute again whenever OpenClaw launches Chrome. ### Attack Path 1. An attacker gains control over, or influences, the arguments passed to `install-browser.sh`. 2. The attacker supplies a crafted value through `--libs-dir` or ...[truncated 1063 chars]- Remediation
View remediation
"$WRAPPER" chmod 700 "$WRAPPER" ``` Additionally, reject unsafe path values before generating the wrapper: ```bash validate_path() { local value="$1" if [[ "$value" == *$'\n'* || "$value" == *$'\r'* ]]; then echo "ERROR: Path contains prohibited control characters" >&2 exit 1 fi } ``` ]]>
