T09 · Insecure Skill Coding Practices
- Location
scripts/tikhub.py:296- Finding
Shell Command Injection in Background Whisper Transcription
- Content
View full analysis
{log_file} 2>&1 &" print(f"🚀 Whisper 后台转写启动,日志: {log_file}") subprocess.run(nohup_cmd, shell=True) ``` ### Technical Analysis The function constructs a command string by joining an argument list and then executes that string with `shell=True`. Values such as `audio_path`, `model`, and `language` are not shell-escaped or restricted to safe values. Because the resulting string is interpreted by a command shell, shell metacharacters in any attacker-influenced argument can introduce additional commands. Using a Python list initially does not provide protection because the list is converted back into an unquoted string before execution. The log-file path is also incorporated into the shell command without quoting. Although `os.path.basename()` removes directory components, it does not remove shell metacharacters. ### Attack Path 1. An attacker causes the Agent or an integrating application to call `whisper_transcribe()` with a crafted `audio_path`, `model`, or `language`. 2. The supplied value contains shell syntax, such as a command separator followed by an attacker-selected command. 3. The function joins the arguments into `nohup_cmd` without quoting or validation. 4. `subprocess.run(..., shell=True)` passes the command to the system shell. 5. The shell interprets the injected syntax and executes the additional command with the privileges of the Agent process. ### Impact Assessment Successful exploitation permits arbitrary local command execution with the same op ...[truncated 637 chars]- Remediation
View remediation
