T03 · Remote Payload Retrieval and Execution
- Location
scripts/nvm-auto-switch.sh:54- Finding
Unverified Remote NVM Installer Is Piped Directly to Bash
- Content
View full analysis
Vulnerability Details
File Location:
scripts/nvm-auto-switch.sh, line 54
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Highbash curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.7/install.sh | bashTechnical Analysis
When NVM is unavailable, the script downloads an installation script from
raw.githubusercontent.comand immediately pipes the response into Bash. The downloaded content is not saved for inspection, and its checksum or cryptographic signature is not verified before execution. The command also lacks fail-closed options such as--fail, meaning an unexpected HTTP response could be passed to the shell.The URL refers to the established
nvm-sh/nvmrepository and pins version tagv0.39.7, which reduces accidental version drift. However, a mutable tag is not a cryptographic integrity control. The effective code executed by the Skill remains dependent on externally delivered content and could change after the packaged Skill has been reviewed.Automatic NVM installation supports the Skill's declared functionality, but executing unverified network content is not the minimum-risk mechanism required to provide that functionality. The payload runs with all permissions of the user invoking the Skill.
Line 63 also displays the same unsafe installation command after an installation failure:
bash echo "Install command: curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.7/install.sh | bash"This second occurrence does not execute the command itself, but it encourages users to repeat the unsafe installation pattern manually.
Attack Path
- A user invokes
scripts/nvm-auto-switch.shfor a project containing anengines.noderequirement. - The script determines that the
nvmcommand is unavailable. - An attacker compromises a relevant delivery component, such as the upstream repository or account, the referenced tag, or the trus ...[truncated 1073 chars]
- A user invokes
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | bashexecution pattern. - Prefer installation through a trusted operating-system package manager where supported.
- If downloading the upstream installer is necessary:
- Use strict transport and error handling, such as
curl --fail --show-error --location --proto '=https'. - Download the installer to a securely created local file instead of piping it to a shell.
- Pin and verify a trusted cryptographic checksum or upstream signature before execution.
- Abort on any download or verification failure.
- Display the source, version, and verification result to the user.
- Obtain explicit user confirmation before executing the verified installer.
- Remove the temporary installer safely afterward.
- Use strict transport and error handling, such as
- Replace the line 63 guidance with verified, non-pipelined installation instructions.
- Consider making NVM installation an explicit prerequisite and exiting with safe manual guidance when it is absent.
- Document that remote installation runs code with the invoking user's privileges and must not be performed from an unverified source.
- Remove the direct
