T09 · Insecure Skill Coding Practices
- Location
scripts/docker.sh:9- Finding
Shell Command Injection Through Untrusted Docker Arguments
- Content
View full analysis
&1; then echo "Done!" exit 0 fi ``` ```bash echo "Trying: docker pull $MIRROR_PATH" if sg docker -c "docker pull $MIRROR_PATH" 2>&1; then # Success — tag back to original image name and clean up echo "Tagging $MIRROR_PATH -> $IMAGE" sg docker -c "docker tag '$MIRROR_PATH' '$IMAGE'" 2>/dev/null echo "Cleaning up" sg docker -c "docker rmi '$MIRROR_PATH'" 2>/dev/null echo "Done!" exit 0 fi ``` ### Technical Analysis The script incorporates user-controlled arguments into strings passed to `sg docker -c`. The `-c` option causes a shell to parse the supplied string again. Consequently, shell metacharacters contained in `$*`, `$IMAGE`, or the derived `$MIRROR_PATH` can become command separators, substitutions, or redirections during this second parsing stage. The quotes surrounding the outer Bash expansion do not prevent injection because they only ensure that the constructed text is passed to `sg` as one argument. The shell started by `sg -c` subsequently reparses that text as executable shell syntax. The `docker tag` and `docker rmi` commands attempt to surround values with single quotes, but these quotes are themselves part of the generated command string. An image argument containing a single quote can terminate the quoted section and inject additional shell syntax. ### Attack Path 1. An attacker influences an argument supplied to `scripts/docker.sh`, either as an image name or as an argument to a forwarded Docker command. 2. The attac ...[truncated 1474 chars]- Remediation
View remediation
