T09 · Insecure Skill Coding Practices
- Location
scripts/audit.sh:75- Finding
Python Code Injection Through an Attacker-Controlled Audit Directory Path
- Content
View full analysis
/dev/null; then PAPER_COUNT=$(python3 -c "import json; d=json.load(open('$INDEX')); print(len(d.get('papers', d if isinstance(d, list) else [])))") echo "index.json entries: $PAPER_COUNT" MISSING=$(python3 -c " import json, os d = json.load(open('$INDEX')) papers = d.get('papers', d if isinstance(d, list) else []) for p in papers: for key in ['pdf_path', 'markdown_path']: path = p.get(key, '') full = os.path.join('$REFDIR', path) if path and not os.path.exists(full): print(f'Missing: {path}') " 2>/dev/null) DUPES=$(python3 -c " import json d = json.load(open('$INDEX')) papers = d.get('papers', d if isinstance(d, list) else []) ids = [p.get('id','') for p in papers] seen = set() for i in ids: if i in seen: print(f'Duplicate ID: {i}') seen.add(i) " 2>/dev/null) ``` ### Technical Analysis The script embeds the values of `INDEX` and `REFDIR` directly into Python source passed to `python3 -c`. Shell double quoting does not make these values safe inside the resulting Python program. If an audited directory name contains a single quote followed by valid Python syntax, the value can terminate the Python string literal and introduce additional statements. The injected Python executes with the same operating-system identity and permissions as the audit process. The issue affects multiple Python invocations. Escaping only one invocation would therefore be insufficient. ### Attack Path 1. An attacker creates or supplies a references directory whose path contains a crafted Python payload. 2. The attac ...[truncated 904 chars]- Remediation
View remediation
