T09 · Insecure Skill Coding Practices
- Location
scripts/start-url-token-web-terminal.sh:18- Finding
Arbitrary Code Execution Through a Predictable Sourced State File
- Content
View full analysis
/dev/null 2>&1 || true else if [[ -n "${PROXY_PID:-}" ]] && kill -0 "${PROXY_PID}" 2>/dev/null; then kill "${PROXY_PID}" 2>/dev/null || true fi if [[ -n "${TTYD_PID:-}" ]] && kill -0 "${TTYD_PID}" 2>/dev/null; then kill "${TTYD_PID}" 2>/dev/null || true fi if [[ -n "${RUNTIME_DIR:-}" ]] && [[ -d "${RUNTIME_DIR}" ]]; then rm -rf "${RUNTIME_DIR}" || true fi fi rm -f "$state_file" } ``` Additional code paths also source the same state file: ```bash # shellcheck disable=SC1090 source "$STATE_FILE" ``` ### Technical Analysis The state-file path is derived predictably from the session name and placed directly under the shared `/tmp` directory. The script checks only whether the path exists; it does not verify that the file: - Was created by the current launcher process. - Is owned by the current user. - Has restrictive permissions. - Is a regular file rather than a symbolic link. - Contains only expected declarative fields. The Bash `source` command evaluates the entire file as shell code. Consequently, any local user who can create or replace the predictable state file can inject arbitrary commands that execute with the privileges of the user running the launcher. The subsequent execution of `bash -lc "$CLEANUP_CMD"` co ...[truncated 1082 chars]- Remediation
View remediation
