T09 · Insecure Skill Coding Practices
- Location
scripts/upload-image.sh:18- Finding
Feishu Bearer Token Stored in a Predictable, Insecure Temporary File
- Content
View full analysis
/dev/null) local TOKEN=$(cat "$TOKEN_CACHE" | python3 -c "import sys,json; print(json.load(sys.stdin).get('token',''))" 2>/dev/null) if [ -n "$TOKEN" ] && [ "$NOW" -lt "$((EXPIRES_AT - 300))" ]; then echo "$TOKEN" return 0 fi fi ``` ```bash echo "{\"token\":\"$TOKEN\",\"expires_at\":$((NOW + EXPIRES_IN - 300))}" > "$TOKEN_CACHE" ``` ### Technical Analysis The script stores a reusable Feishu application access token in a fixed path under the shared `/tmp` directory. It does not set restrictive permissions, verify ownership, reject symbolic links, or create the file atomically. The effective permissions depend on the invoking process's `umask`. A permissive `umask` could make the token readable by other local users. Because the path is predictable, another local user may also attempt to create the cache path or a symbolic link before the script writes to it. If the operating system does not block the operation through protections such as `fs.protected_symlinks` or `fs.protected_regular`, a more privileged invocation may follow the attacker-controlled path. The cached value is an application bearer token. It is not merely operational metadata and should be protected to the same degree as other credentials. ### Attack Path 1. A local attacker predicts the fixed cache path `/tmp/feishu_app_token.cache`. 2. The attacker either monitors the path for a permissively created file or pre-creates the path as a regular file or symbolic link. 3. A user or privileged autom ...[truncated 1024 chars]- Remediation
View remediation
