T09 · Insecure Skill Coding Practices
- Location
scripts/make-call.sh:106- Finding
Arbitrary Python Code Execution Through Call Message or Voice Arguments
- Content
View full analysis
$MESSAGE" if [[ "$URGENT" == "true" ]]; then TWIML="${TWIML}This is an urgent message. Please respond immediately." fi TWIML="${TWIML}" # URL encode TwiML TWIML_ENCODED=$(python3 -c "import urllib.parse; print(urllib.parse.quote('''$TWIML'''))") ``` ### Technical Analysis The `--message` and `--voice` command-line arguments are incorporated into `TWIML`, which is then directly interpolated into Python source supplied to `python3 -c`. Shell quoting does not make the interpolated content safe as Python source. An attacker who can influence either argument can include a sequence such as `'''` to terminate the Python triple-quoted string and append attacker-selected Python statements. Those statements can invoke operating-system commands, read files, modify user-owned data, or access secrets available to the process. This is a direct local code-execution vulnerability rather than ordinary malformed-input handling. ### Attack Path 1. An attacker supplies or causes an agent to supply a malicious `--message` or `--voice` value. 2. The script embeds that value into the `TWIML` shell variable. 3. The complete value is inserted into the source string passed to `python3 -c`. 4. The malicious value terminates the intended Python string literal and introduces additional Python code. 5. Python executes the injected statements with the identity and environment of the user running the skill. ### Impact Assessment Successful exploitation provides arbitrary code execution under the invoking user's privileges. The attacker could: - Read the Twilio Auth Token and Account SID from the process environment or configuration file. - Ma ...[truncated 321 chars]- Remediation
View remediation
