T09 · Insecure Skill Coding Practices
- Location
scripts/web-trending.sh:10- Finding
Shell Command Injection Through the Trending Limit Argument
- Content
View full analysis
&1) || true ``` ### Technical Analysis The second command-line argument is assigned directly to `LIMIT` without validating that it is numeric. It is then concatenated into a shell command string and executed with `eval`. Quoting `"$CMD"` does not make this safe because `eval` reparses the resulting string as shell syntax. Shell separators, command substitutions, redirections, or other metacharacters placed in `LIMIT` therefore become executable syntax. ### Attack Path 1. An attacker, untrusted prompt, or calling process controls the limit argument passed to `web-trending.sh`. 2. The attacker supplies a value containing a valid limit followed by shell syntax, such as a command s ...[truncated 576 chars]- Remediation
View remediation
100 )); then echo "Limit must be an integer from 1 to 100" >&2 exit 2 fi case "$PLATFORM" in twitter) CMD=(opencli twitter trending --limit "$LIMIT" -f md) ;; zhihu) CMD=(opencli zhihu hot --limit "$LIMIT" -f md) ;; hackernews) CMD=(opencli hackernews top --limit "$LIMIT" -f md) ;; # Define the remaining permitted commands in the same manner. esac result=$("${CMD[@]}" 2>&1) || true ``` Add regression tests using shell metacharacters, command substitutions, whitespace, negative numbers, and excessively large values. ]]>
