T09 · Insecure Skill Coding Practices
- Location
scripts/adjust.sh:45- Finding
Arbitrary Command Execution Through Unsafe eval in adjust.sh
- Content
View full analysis
$output" eval "$cmd" ``` ### Technical Analysis The script builds an ImageMagick command as a string containing user-controlled input and then passes that string to `eval`. The shell therefore parses the command twice: 1. Once while the command string is assembled. 2. Again when `eval` interprets the completed string as shell source code. The embedded quotation marks do not safely quote hostile values during the second parsing stage. Values such as the input path, output path, rotation, saturation, blur geometry, border geometry, and border color can introduce quotation marks, command separators, command substitutions, redirections, or other shell syntax. The affected option values are not validated against their documented numeric, color, or geometry formats. Consequently, the flaw is not limited to unusual filenames. ### Attack Path 1. An attacker obtains control over an argument passed to `adjust.sh`, such as the output filename or an adjustment option. 2. The attacker supplies a value that closes the generated quotation context and appends a shell command, for example an output argument structurally equiv ...[truncated 960 chars]- Remediation
View remediation
