T09 · Insecure Skill Coding Practices
- Location
scripts/_temu_token_store.py:28- Finding
Temu access tokens are stored in plaintext without restrictive file permissions
- Content
View full analysis
str: return os.environ.get("TEMU_TOKEN_STORE_PATH", DEFAULT_STORE_PATH) ``` ```python def _save_store(data: dict) -> None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` ```python entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ``` ### Technical Analysis The token store serializes Temu access tokens directly into a plaintext JSON file under `~/.linkfox/temu-access-tokens.json`. The file is opened with the ordinary Python `open()` API without explicitly setting a restrictive permission mode. Consequently, the resulting permissions depend on the process umask. In environments with a permissive umask, the token file may be readable by other local users or processes. The implementation also does not verify that an existing token-store path is a regular file owned by the current user, leaving additional symlink and file-replacement concerns in hostile shared environments. These access tokens are subsequently used to access Temu order, shipping, customization, and potentially decrypted shipping-information APIs. They must therefore be treated as high-value credentials. ### Attack Path 1. A user saves a Temu token through `save_temu_access_token.py`. 2. `_save_store()` writes the raw token to `~/.linkfox/temu-access-tok ...[truncated 1042 chars]- Remediation
View remediation
