T09 · Insecure Skill Coding Practices
- Location
cashflow_rollup.py:27- Finding
Terminal Escape-Sequence Injection Through Cashflow Report Fields
- Content
View full analysis
= 0: months[month]["in"] += amount else: spend = -amount months[month]["out"] += spend categories[category] += spend merchants[merchant] += spend ``` ```python print("\nTop categories") for name, value in sorted(categories.items(), key=lambda item: item[1], reverse=True)[:5]: print(f"- {name}: {value:,.2f}") print("\nTop merchants") for name, value in sorted(merchants.items(), key=lambda item: item[1], reverse=True)[:5]: print(f"- {name}: {value:,.2f}") ``` ### Technical Analysis The `merchant` and `category` fields are read from a user-supplied CSV and used as dictionary keys without validation. When the report is generated, these values are interpolated directly into terminal output. Calling `.strip()` only removes leading and trailing whitespace. It does not remove embedded newlines, carriage returns, ANSI escape sequences, OSC sequences, or other C0/C1 control characters. A crafted field can therefore alter the terminal display, overwrite or conceal preceding output, create misleading report lines, or invoke terminal-specific features. The Python formatting operation does not execute shell commands directly. More consequential effects, such as clipboard manipulation or interactive links, depend ...[truncated 1312 chars]- Remediation
View remediation
