T09 · Insecure Skill Coding Practices
- Location
scripts/doc-edit.sh:61- Finding
Arbitrary Command Execution Through GNU sed Expression Injection
- Content
View full analysis
Vulnerability Details
File Location:
scripts/doc-edit.sh:61-67
Vulnerability Type: Command injection through dynamically constructed sed expressions
Risk Level: HighVulnerable Code
bash PATTERN="$1" REPLACEMENT="$2" TMPFILE=$(mktemp --suffix=.md) # Read, replace, and write back "$SCRIPT_DIR/doc-read.sh" "$FILE" markdown | sed "s/$PATTERN/$REPLACEMENT/g" > "$TMPFILE" "$SCRIPT_DIR/doc-write.sh" "$FILE" "$TMPFILE" markdownTechnical Analysis
Both
PATTERNandREPLACEMENTare supplied by the caller and interpolated directly into a sed program. Shell quoting prevents a second round of shell expansion, but it does not make the values safe inside sed syntax.An attacker can include sed delimiters, command separators, flags, backslashes, or newlines in these values. On GNU sed, the
esubstitution flag executes the resulting pattern space as a shell command. A crafted replacement can terminate the intended substitution, introduce theeflag, and comment out or otherwise neutralize the remaining generated syntax.This is more severe than ordinary regular-expression injection because the generated sed program can cross the boundary from text manipulation into local command execution.
Attack Path
- The attacker influences the arguments supplied to the documented
replaceoperation. - The Agent invokes a command equivalent to:
bash ./scripts/doc-edit.sh document.docx replace "target" "crafted sed payload" - The script inserts the attacker-controlled values into:
bash sed "s/$PATTERN/$REPLACEMENT/g" - The crafted replacement closes the intended expression and introduces GNU sed's
eexecution flag. - When a matching line is processed, sed passes the generated text to a shell.
- The injected command executes with the same operating-system privileges and environment as the Agent process ...[truncated 558 chars]
- The attacker influences the arguments supplied to the documented
- Remediation
View remediation
Remediation Suggestions
- Do not generate a sed program by directly interpolating untrusted values.
- Implement literal replacement using a language API that separates data from executable replacement syntax.
- If regular-expression replacement is an intentional feature, explicitly document it and safely escape:
- The selected sed delimiter
- Backslashes
- Ampersands in replacement strings
- Newlines and command separators
- Any syntax capable of adding sed flags or commands
- Do not permit GNU sed's
eflag or attacker-controlled sed programs. - Pass pattern and replacement values through environment variables or another data-only channel to a dedicated replacement implementation.
- Write the edited document to a separate temporary output and atomically replace the original only after every conversion succeeds.
- Add cleanup traps for temporary files.
- Add regression tests covering delimiters, semicolons, newlines, backslashes, ampersands, malformed regular expressions, and attempted
e-flag injection.
