T09 · Insecure Skill Coding Practices
- Location
scripts/tikhub.py:286- Finding
Shell Command Injection in Background Whisper Transcription
- Content
View full analysis
{log_file} 2>&1 &" print(f"🚀 Whisper 后台转写启动,日志: {log_file}") subprocess.run(nohup_cmd, shell=True) ``` ### Technical Analysis The public `whisper_transcribe` function constructs a command by joining arguments into one shell command string and executes it with `shell=True`. Parameters such as `audio_path`, `model`, and `language` are inserted without shell escaping, quoting, or allowlist validation. Because the command is interpreted by a shell, metacharacters contained in an attacker-controlled argument can terminate or alter the intended `whisper` command and introduce additional commands. Using `os.path.basename()` for the log filename does not protect the original `audio_path` included in `cmd`. The synchronous branch uses an argument list without `shell=True` and is not affected by this specific flaw. ### Attack Path 1. An attacker obtains influence over an audio path passed to `whisper_transcribe`, directly or through an integration that accepts user-selected filenames. 2. The attacker supplies a path containing shell metacharacters and an additional command, for example a filename structured as `audio.wav; attacker_command; #`. 3. `whisper_transcribe` places that value into `cmd`. 4. The function joins `cmd` into `nohup_cmd` without escaping. 5. `subprocess.run(..., shell=True)` asks the operating-system shell to interpret the resulting text. 6. The shell executes the injected command with the same operating-sy ...[truncated 529 chars]- Remediation
View remediation
