T09 · Insecure Skill Coding Practices
- Location
scripts/knowledge_base_manager.py:454- Finding
Unsafe Pickle Deserialization Enables Arbitrary Code Execution
- Content
View full analysis
Dict[str, Any]: """Load knowledge-base metadata.""" if os.path.exists(self.kb_metadata_file): try: with open(self.kb_metadata_file, 'rb') as f: return pickle.load(f) except Exception as e: logger.warning(f"Failed to load knowledge-base metadata: {str(e)}") return {"chunk_size": DEFAULT_CHUNK_SIZE} ``` ```python if os.path.exists(self.index_file) and os.path.exists(self.metadata_file): logger.info(f"Loading existing FAISS index: {self.index_file}") with open(self.index_file, 'rb') as f: vectors_data = pickle.load(f) with open(self.metadata_file, 'rb') as f: self.metadata = pickle.load(f) ``` ```python kb_metadata_file = os.path.join( vectordb_dir, KnowledgeBaseManager.KB_METADATA_FILE ) chunk_size = DEFAULT_CHUNK_SIZE if os.path.exists(kb_metadata_file): try: with open(kb_metadata_file, 'rb') as f: kb_metadata = pickle.load(f) chunk_size = kb_metadata.get( "chunk_size", DEFAULT_CHUNK_SIZE ) except Exception: pass ``` ### Technical Analysis Python pickle data is executable serialization rather than a data-only format. During `pickle.load()`, objects can invoke attacker-defined reconstruction functions through methods such as `__reduce__`. A malicious pickle can therefore execute arbitrary Python callables before the application validates or uses the resulting object. The implementation loads three persistent files without validating their origin, ownership, type, permissions, or integrity: - `vectordb/kb_metadata.pkl` - `vectordb/fais ...[truncated 1742 chars]- Remediation
View remediation
