T09 · Insecure Skill Coding Practices
- Location
download.sh:95- Finding
Arbitrary Local Code Execution Through JavaScript Source Injection
- Content
View full analysis
0 ? ((completed / total) * 100).toFixed(1) : 0; const filename = s.files && s.files[0] ? s.files[0].path : 'unknown'; const name = filename.split('/').pop(); console.log(JSON.stringify({ success: true, gid: '$GID', status: s.status, name: name, total: total, completed: completed, speed: speed, speedHuman: speed > 1024*1024 ? (speed/1024/1024).toFixed(1)+'MB/s' : (speed/1024).toFixed(1)+'KB/s', percent: percent + '%', eta: speed > 0 ? Math.round((total - completed) / speed) + 's' : null })); " ``` A second vulnerable interpolation occurs in the wait and watch implementation: ```bash node -e " const r = JSON.parse('$RESPONSE'); const s = r.result || {}; const status = s.status; const total = parseInt(s.totalLength) || 0; const completed = parseInt(s.completedLength) || 0; const speed = parseInt(s.downloadSpeed) || 0; const percent = total > 0 ? ((completed / total) * 100).toFixed(1) : 0; const filename = s.files && s.files[0] ? s.files[0].path.split('/').pop() : 'unknown'; const dir = s.dir || '$DIR'; const totalSize = (total / 1024 / 1024).toFixed(2); const completedSize = (completed / 1024 / 1024).toFixed(2); if (status === 'complete') { console.log(''); console.log('━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━'); console.log('✅ 下载完成!'); console.log('━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━'); cons ...[truncated 3107 chars]- Remediation
View remediation
{ input += chunk; }); process.stdin.on("end", () => { try { const response = JSON.parse(input); // Process response values only as data. } catch (error) { console.error(JSON.stringify({ success: false, error: "Invalid RPC response" })); process.exit(1); } }); ' ``` Pass GID and directory values as separate environment variables or command-line arguments rather than embedding them in source. Validate GIDs against the expected Aria2 GID format before use. Additional hardening should include: 1. Reject malformed or unexpectedly large RPC responses. 2. Validate the RPC response schema and field types before processing. 3. Avoid `node -e` when a fixed, separately stored script can be used. 4. Require authenticated and trusted RPC endpoints. 5. Use TLS certificate verification for remote RPC services. 6. Run the utility under a minimally privileged account. ]]>
