T09 · Insecure Skill Coding Practices
- Location
SKILL.md:106- Finding
World-Writable Permissions Applied Recursively to the Music Library
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 106
Vulnerability Type: Unsafe recursive filesystem permissions
Risk Level: MediumVulnerable Code Snippet:
bash chmod -R 777 /vol1/1000/Docker/music-player/music/Technical Analysis
The troubleshooting documentation instructs users to recursively apply mode
777to the entire music library. This grants read, write, and execute permissions to the owner, group, and every other local user.Recursive application also changes every nested file and directory. Consequently, unrelated local accounts and compromised services can modify or delete library content. Files unnecessarily receive execute permission as well. The instruction violates least-privilege principles and is particularly unsafe on a multi-user NAS.
This command is documented rather than executed automatically, so exploitation requires an administrator or sufficiently privileged user to follow the instruction.
Attack Path
- A privileged user follows the troubleshooting instruction and runs the documented command.
- The music directory and all existing nested content become world-writable.
- An untrusted local account or compromised low-privileged service accesses the directory.
- The attacker replaces, deletes, or adds media files and other content.
- Mopidy or another process subsequently reads, indexes, or processes the attacker-controlled content.
Impact Assessment
Exploitation does not directly grant root privileges. It grants any local account or process the ability to alter the complete music-library tree after the command has been applied. This can result in loss of integrity and availability, unauthorized content insertion, library corruption, and potential exposure to malicious files processed by Mopidy or associated media tooling.
The affected scope is
/vol1/1000/Docker/music-player/music/and all descendants present when the recursive command is ...[truncated 9 chars]- Remediation
View remediation
Remediation Suggestions
Remove the
chmod -R 777recommendation and configure ownership around the actual Mopidy service account and group.- Determine the UID and GID used by Mopidy inside the container.
- Assign the music directory to an appropriate trusted owner and Mopidy-accessible group.
- Grant only the permissions required by the deployment. For a read-only library, use directory mode
750and file mode640, adjusted as necessary for the actual owner and group. - If Mopidy must write metadata or generated content, grant group write access only to the specific directories that require it rather than to the complete library.
- Set directory and file modes separately instead of recursively applying one mode:
bash find /vol1/1000/Docker/music-player/music/ -type d -exec chmod 750 {} \; find /vol1/1000/Docker/music-player/music/ -type f -exec chmod 640 {} \; - Document backup and permission-verification steps before changing an existing library.
