T09 · Insecure Skill Coding Practices
- Location
scripts/_temu_token_store.py:8- Finding
Reusable Temu Access Tokens Stored in Plaintext Without Restrictive File Permissions
- Content
View full analysis
str: return os.environ.get("TEMU_TOKEN_STORE_PATH", DEFAULT_STORE_PATH) ``` ```python def _save_store(data: dict) -> None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` ```python entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ``` ### Technical Analysis The token store writes reusable Temu access tokens directly to a plaintext JSON file. Neither the parent directory nor the token file is created with an explicit restrictive permission mode. The effective permissions therefore depend on the process umask and any pre-existing path permissions. On a multi-user system or permissively configured environment, another local user or process may be able to read the credential file. The implementation also does not verify whether an environment-provided `TEMU_TOKEN_STORE_PATH` points to a secure, user-owned location. Because the stored value is an actual bearer-style access token rather than a non-sensitive identifier, possession may be sufficient to make authorized Temu API calls within the token's granted scopes. ### Attack Path 1. A user invokes `save_temu_access_token.py` with a valid Temu access token. 2. `_save_store()` creates or overwrites the JSON token store using ordinary default permissions. 3. The resulting file is readable by another local principal due to the process umask, inherited director ...[truncated 756 chars]- Remediation
View remediation
