T09 · Insecure Skill Coding Practices
- Location
scripts/send_audio.sh:31- Finding
Predictable Temporary File Enables Local Symlink Attacks
- Content
View full analysis
[voice]}" CHAT_ID="${2:?chat_id required}" VOICE="${3:-zh-CN-XiaoyiNeural}" TMP_FILE="/tmp/feishu_audio_$$.mp3" fi ``` The predictable path is subsequently written to and removed: ```bash "$TTS_BIN" -t "$TEXT" -f "$TMP_FILE" -v "$VOICE" -l "$(echo $VOICE | cut -d- -f1-2)" 2>&1 ``` ```bash if [[ "$FILE_MODE" == false ]]; then rm -f "$TMP_FILE"; fi ``` ### Technical Analysis The script creates a temporary filename in the shared `/tmp` directory using only its process ID. Process IDs are predictable, and the script does not securely create the file before passing its path to `node-edge-tts`. A local attacker may create a symbolic link at the anticipated pathname before the TTS process writes its output. The exact consequences depend on how `node-edge-tts` opens the output path. If it follows symbolic links and truncates the destination, the script can overwrite a file selected by the attacker with the privileges of the user executing the Skill. The cleanup command is quoted and does not itself contain shell-injection behavior, but it does not mitigate the prior unsafe write. ### Attack Path 1. A local attacker monitors or predicts the PID of a future Skill process. 2. The attacker creates `/tmp/feishu_audio_.mp3` a ...[truncated 1022 chars]- Remediation
View remediation
