T09 · Insecure Skill Coding Practices
- Location
scripts/gen_config.js:102- Finding
Shell Command Injection Through the Subscription URL
- Content
View full analysis
/tmp/injection-proof; # ``` 3. The resulting shell command is effectively interpreted as: ```sh curl -sL ''; id > /tmp/injection-proof; #' -o /tmp/sub_raw.txt ``` 4. The shell executes the injected command. 5. If the generator was launched with elevated privileges, the injected command executes with those same privileges. ### Impact Assessment Successful exploitation provides arbitrary command execution with the privileges of the Node.js process. When run as root, an attacker could read or alter protected files, install additional services, replace binaries, steal proxy credentials, establish persistence, or fully compromise the host. ]]>- Remediation
View remediation
