T09 · Insecure Skill Coding Practices
- Location
receive.sh:8- Finding
Unvalidated output name permits path traversal and arbitrary file overwrite
- Content
View full analysis
Vulnerability Details
File Location:
receive.sh, lines 8-44
Vulnerability Type: Path traversal and unsafe temporary-file handling
Risk Level: HighVulnerable Code
bash NAME="$3" TYPE="${4:-tar}" echo "[+] Downloading / 正在下载..." curl -s -o "/tmp/${NAME}.enc" "$URL" echo "[+] Decrypting / 正在解密..." if [ "$TYPE" = "tar" ]; then openssl enc -aes-256-cbc -d -pbkdf2 -in "/tmp/${NAME}.enc" -out "/tmp/${NAME}.tar.gz" -k "$PASSWORD" echo "[+] Extracting to skills/ / 正在解压到 skills/..." mkdir -p "skills/${NAME}" tar xzf "/tmp/${NAME}.tar.gz" -C "skills/${NAME}/" rm -f "/tmp/${NAME}.enc" "/tmp/${NAME}.tar.gz" else openssl enc -aes-256-cbc -d -pbkdf2 -in "/tmp/${NAME}.enc" -out "/tmp/${NAME}" -k "$PASSWORD" rm -f "/tmp/${NAME}.enc" fiTechnical Analysis
The script uses the attacker-influenced
NAMEargument directly in filesystem paths without restricting it to a safe basename. Quoting prevents shell-token injection, but it does not prevent filesystem traversal. Values containing/,.., or absolute-path-like components can escape both/tmpandskills.In file mode, the decrypted content is written to
/tmp/${NAME}. For example, a name containing traversal components can resolve to a file outside/tmp. In tar mode, traversal affects the encrypted input path, decrypted archive path, installation directory, and cleanup paths.The script also uses deterministic names in the shared
/tmpdirectory instead of a private directory created withmktemp. A local user may pre-create one of these paths as a symbolic link. Utilities opening the path for output can then truncate or overwrite the symlink target with the privileges of the user running the receiver.The only download validation is a regular file existence test:
bash if [ ! -f "/tmp/${NAME}.enc" ]; thenThis does not establish that the file was securely created by this process. ...[truncated 1594 chars]
- Remediation
View remediation
Remediation Suggestions
- Reject names that are not strict basenames. Use an allowlist such as
^[A-Za-z0-9][A-Za-z0-9._-]{0,63}$. - Explicitly reject
/,\,.., control characters, leading hyphens, and empty names. - Create a private temporary directory using
mktemp -d, give it restrictive permissions, and place all downloaded and decrypted files inside it. - Register a quoted
trapto remove only the private directory on exit. - Resolve the final installation destination canonically and verify that it remains beneath the intended
skillsroot. - Refuse to overwrite an existing installation unless the user explicitly authorizes replacement.
- Avoid predictable files directly under
/tmp; use exclusive file creation and reject symbolic links. - Run the script as an unprivileged account and document that it must not be run with
sudoor as root. - Validate
TYPEagainst an explicit allowlist rather than treating every non-tarvalue as file mode.
A safer pattern is:
bash case "$NAME" in ""|*[!A-Za-z0-9._-]*|*..*) exit 1 ;; esac case "$TYPE" in tar|file) ;; *) exit 1 ;; esac WORKDIR="$(mktemp -d)" chmod 700 "$WORKDIR" trap 'rm -rf -- "$WORKDIR"' EXIT- Reject names that are not strict basenames. Use an allowlist such as
