T09 · Insecure Skill Coding Practices
- Location
scripts/mysql_backup.sh:71- Finding
Arbitrary Shell Command Execution in the Database Backup Script
- Content
View full analysis
Vulnerability Details
File Location:
scripts/mysql_backup.sh, lines 71-84
Vulnerability Type: OS command injection through unsafe command construction andeval
Risk Level: HighVulnerable Code
bash # Build mysqldump command MYSQLDUMP_CMD="mysqldump -h $HOST -P $PORT -u $USER -p$PASSWORD $DATABASE" # Add compression if requested if [[ "$COMPRESS" == true ]]; then MYSQLDUMP_CMD="$MYSQLDUMP_CMD | gzip > ${OUTPUT}.gz" OUTPUT="${OUTPUT}.gz" else MYSQLDUMP_CMD="$MYSQLDUMP_CMD > $OUTPUT" fi # Execute backup echo "Backing up database: $DATABASE" echo "Output file: $OUTPUT" eval $MYSQLDUMP_CMDTechnical Analysis
The script constructs a shell command by interpolating values obtained from command-line arguments into a string. The string is subsequently passed to
eval, causing the shell to parse its contents again as executable shell syntax.The values supplied through
--host,--port,--user,--password,--database, and--outputare not validated or safely quoted. Consequently, shell metacharacters, command substitutions, redirections, pipelines, or command separators included in these values are interpreted byevalrather than passed literally tomysqldump.Both the compressed and uncompressed branches are vulnerable. In particular,
OUTPUTis inserted directly into a redirection expression, while all connection parameters become part of the reparsed command string.Attack Path
- An attacker influences one of the arguments supplied to
mysql_backup.sh, such as the database name, host, password, or output path. - The malicious value is inserted into
MYSQLDUMP_CMDwithout safe argument separation. - The script invokes
eval $MYSQLDUMP_CMD. evalreparses shell syntax contained in the attacker-controlled value.- The injected command executes with the operating-system privileges of the user or Agent running the Skill.
Impact Ass
...[truncated 571 chars]
- An attacker influences one of the arguments supplied to
- Remediation
View remediation
Remediation Suggestions
- Remove
evalentirely. - Build the
mysqldumpinvocation using a Bash array so each value remains one argument. - Perform redirection directly rather than storing redirection operators in a command string.
- Implement the compression pipeline explicitly and enable
set -o pipefail. - Validate
PORTas a numeric value and enforce an appropriate range. - Validate output paths against the directories the Skill is authorized to write.
- Pass credentials through a protected MySQL option file or login path rather than the command line.
A safer structure is:
bash set -euo pipefail args=(-h "$HOST" -P "$PORT" -u "$USER" "$DATABASE") if [[ "$COMPRESS" == true ]]; then mysqldump "${args[@]}" | gzip > "${OUTPUT}.gz" else mysqldump "${args[@]}" > "$OUTPUT" fiAuthentication should be supplied separately through a mode-
0600option file ormysql_config_editor.- Remove
