T09 · Insecure Skill Coding Practices
- Location
server.py:114- Finding
Python Code Injection Through a User-Controlled Image Filename
- Content
View full analysis
str: return _INLINE_PREAMBLE + _INLINE_BODY.format(container_img_path=container_img_path) def _run_container(image: str, host_image_path: str, timeout: int = 300) -> dict: """Run OCR inside an ephemeral Docker container.""" apath = Path(host_image_path).resolve() if not apath.exists(): return {"status": "error", "message": f"file not found: {host_image_path}"} host_dir = str(apath.parent) container_img = f"/data/{apath.name}" script = _build_inline_script(container_img) ``` The generated script is subsequently executed using: ```python image, "python3", "-c", script, ``` ### Technical Analysis The `image_path` tool argument controls the filename represented by `apath.name`. That filename is inserted directly into a single-quoted Python string using `str.format()`. No Python-string escaping or safe serialization is applied before the resulting source code is supplied to `python3 -c`. A valid existing filename containing a quote, newline, or other Python syntax can therefore terminate the intended string and inject additional Python statements. Using a subprocess argument array prevents shell injection into the host command, but it does not prevent this separate source-code injection because the attacker-controlled value becomes part of executable Python source. ### Attack Path 1. An attacker creates an existing file ...[truncated 1354 chars]- Remediation
View remediation
