T09 · Insecure Skill Coding Practices
- Location
upload-image.sh:21- Finding
Remote Code Execution Through Unsafe Python Source Interpolation
- Content
View full analysis
/dev/null) ``` ### Technical Analysis The script obtains `RESPONSE` from the external `img.scdn.io` service and interpolates it directly into the source code supplied to `python3 -c`. Although the shell variable is enclosed in double quotes at the shell level, its contents are inserted into a single-quoted Python string: ```python data = json.loads('$RESPONSE') ``` A response containing a single quote can terminate the Python string and introduce additional Python statements. This makes the remote HTTP response executable code rather than treating it exclusively as JSON data. For example, a malicious service response shaped like the following could close the string, complete the existing operation, and append Python code: ```text {}'); __import__("os").system("id"); data={"url":"https://example.invalid/x"}; # ``` After interpolation, the Python program would effectively contain: ```python import json; data = json.loads('{}'); __import__("os").system("id"); data={"url":"https://example.invalid/x"}; #'); print(data.get('url', '')) ``` The vulnerability does not require the image path itself to contain shell syntax. Exploitation depends on control of the upload service's response, such as through compromise of the service, malicious server behavior, or compromise of its delivery infrastructure. HTTPS reduces network interception risk but does not protect against a compromised or intentionally malicious endpoint. The static pre-scan warning concerning `curl | bash` was not ...[truncated 1955 chars]- Remediation
View remediation
/dev/null) ``` Additional hardening should include: 1. Check the `curl` exit status using `--fail` so HTTP errors are not parsed as successful responses. 2. Apply connection and total-operation timeouts to prevent indefinite blocking. 3. Validate that the parsed top-level value is a JSON object and that `url` is a non-empty string. 4. If only known CDN URLs are expected, parse the URL and enforce an HTTPS scheme and an explicit hostname allowlist. 5. Avoid printing the entire server response on failure because it may contain unexpected or sensitive server-generated content. 6. Document clearly that the selected image is transmitted to a third-party service and becomes publicly accessible. 7. Run the Skill with only ordinary user permissions and without unnecessary access to secrets or sensitive directories. ]]>
