T09 · Insecure Skill Coding Practices
- Location
scripts/extractor/multi_site_bridge.js:26- Finding
Shell Command Injection Through Untrusted Article URLs
- Content
View full analysis
`"${u}"`); args.push('--output', `"${outputDir}"`); if (options.json) args.push('--json'); console.log(`🕷️ 调用 multi-site-extractor 抓取 ${urls.length} 篇文章...\n`); const cmd = `python3 "${extractScript}" ${args.join(' ')}`; if (options.json && !options.rewrite && !options.publish) { execSync(cmd, { stdio: 'inherit', env: process.env }); } else { execSync(cmd, { stdio: 'inherit', env: process.env }); } ``` ### Technical Analysis Article URLs are embedded directly into shell command strings passed to `execSync`. Surrounding a value with double quotes does not make it safe for a shell. Command substitutions such as `$(command)` and other shell syntax can still be evaluated inside double quotes. A quotation mark in the input can also terminate the intended argument and introduce additional commands. The vulnerable extractor bridge is used by the `links`, `search`, and `workflow` flows. Consequently, the dangerous value may originate either from a direct CLI argument or from an untrusted search result. The separate `extract` command in `main.js` constructs a shell command from every supplied URL in the same unsafe manner. This is not required for the declared extraction functionality. Node.js can invoke Python directly with an argument array without involving a shell. ### Attack Path 1. An attacker supplies a crafted URL to `links`, `extract`, or `workflow links`, or causes a poisoned URL to appear in search results. 2. The Skill passes ...[truncated 1233 chars]- Remediation
View remediation
