T09 · Insecure Skill Coding Practices
- Location
scripts/_temu_token_store.py:28- Finding
Temu Access Tokens Are Stored in Plaintext Without Restrictive File Permissions
- Content
View full analysis
None: path = store_path() parent = os.path.dirname(path) if parent: os.makedirs(parent, exist_ok=True) with open(path, "w", encoding="utf-8") as f: json.dump(data, f, indent=2, ensure_ascii=False) f.write("\n") ``` The data written by this function includes the complete Temu access token: ```python entry = { "site": site, "managementType": management_type, "tokenPurpose": token_purpose, "accessToken": access_token, "updatedAt": _utc_now(), } ``` ### Technical Analysis The token store defaults to `~/.linkfox/temu-access-tokens.json`. Tokens are serialized directly into a plaintext JSON document. The code creates the parent directory and output file without explicitly applying owner-only permissions. The resulting permissions therefore depend on the process umask and any pre-existing directory or file permissions. In an environment with a permissive umask, shared home directory, container volume, or inherited group-readable file, another local account or process may read the complete Temu access token. The file is also opened through an ordinary path without symlink checks or atomic replacement. If a less-trusted local actor can modify the token-store directory or configured `TEMU_TOKEN_STORE_PATH`, that actor may be able to redirect writes to another filesystem target. ### Attack Path 1. A user invokes `save_temu_access_token.py`, causing a Temu token to be stored in the JSON file. 2. The host's umask or pre-existing filesystem permissions allow another local user or process to read the file. 3. The attacker opens `~/.linkfox/temu-access-tokens.json` and extracts the plaintext `accessToken`. 4. The attacker uses that token with compa ...[truncated 932 chars]- Remediation
View remediation
