T03 · Remote Payload Retrieval and Execution
- Location
data/install.md:25- Finding
Remote Installer Command Executes Mutable Network Content Without Prior Verification
- Content
View full analysis
Vulnerability Details
File Location:
data/install.md, line 25
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalComplete Code Snippet:
yaml command: "curl -fsSL https://get.x-cmd.com | sh"Technical Analysis
The installation metadata defines a command that retrieves content from
https://get.x-cmd.comand passes it directly tosh. The payload is neither pinned to an immutable version nor authenticated with a known checksum or signature before execution.HTTPS protects the connection to the currently authenticated endpoint, but it does not guarantee that the returned installer remains identical to the version reviewed during this audit. If the domain, hosting infrastructure, served installer, DNS resolution, or TLS trust chain is compromised, arbitrary commands can be supplied and executed immediately.
The document claims that downloaded binaries receive SHA-256 verification, but it also acknowledges that this verification occurs after the initial installer has begun executing. Consequently, it cannot establish the integrity of the bootstrap script itself.
This behavior exceeds the minimum privileges and capabilities needed to document or install the package manager. The project already provides lower-risk alternatives, including Homebrew installation and downloading the installer for review before execution.
Attack Path
- A user or agent selects the automatic installation method.
curlrequests the current payload fromget.x-cmd.com.- An attacker compromises or impersonates an element of the remote delivery chain, or modifies the installer hosted at the endpoint.
- The attacker-controlled response is streamed directly into
sh. - The shell executes the response before any meaningful integrity validation of the bootstrap script.
- The payload can inspect or modify resources available to the invoking user and retrieve additional unreview ...[truncated 780 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | shcommand from the installation metadata. - Replace it with a versioned, immutable installer artifact.
- Publish a cryptographic signature or trusted SHA-256 digest through an independent, authenticated channel.
- Download the installer into a safely created temporary file and verify its signature or checksum before invoking a shell.
- Require explicit user approval after verification and, where practical, after source review.
- Prefer a reputable package manager with reviewed and versioned package metadata.
- Ensure agents never execute mutable remote scripts automatically, including in disposable environments.
- Remove the direct
