T09 · Insecure Skill Coding Practices
- Location
scripts/add_to_cart.sh:202- Finding
Arbitrary Local Command Execution Through Python Source Injection
- Content
View full analysis
/dev/null || \ python3 -c "import urllib.parse, sys; print(urllib.parse.quote(sys.argv[1]))" "$raw" } ``` ### Technical Analysis The `url_encode` function places the user-supplied product keyword directly inside a Python program passed to `python3 -c`. Shell quoting does not make the generated Python source safe. A keyword containing a single quote can terminate the Python string and append additional Python statements. For example, an input shaped like the following breaks out of the intended call: ```text '); __import__("os").system(""); # ``` The injected statement is evaluated by the first `python3 -c` invocation. The safe-looking fallback does not mitigate this issue because it only executes if the vulnerable command fails, and injected code may already have run successfully. ### Attack Path 1. An attacker supplies or persuades a user to use a crafted product-search keyword. 2. The script assigns that keyword to `KEYWORD`. 3. `url_encode "$KEYWORD"` passes it to the `raw` local variable. 4. The value is expanded into the source string given to `python3 -c`. 5. A single quote terminates the intended Python string. 6. Attacker-provided Python statements execute with the privileges of the user running the Skill. ### Impact Assessment Successful exploitation provides arbitrary local command execution under the current operating-system user account. Depending on that account's permissions, an attacker could: - Read or modify files accessible to the user. - Access local application configuration and credentials. - Make arbitrary network requests. - Alter other user-owned ...[truncated 260 chars]- Remediation
View remediation
