T09 · Insecure Skill Coding Practices
- Location
references/details.md:406- Finding
Remote Command Injection Through an Unvalidated Rollback Tag
- Content
View full analysis
Vulnerability Details
File Location:
references/details.md, lines 406 and 417-421
Vulnerability Type: Shell command injection across an SSH boundary
Risk Level: HighVulnerable Code
bash BACKUP_TAG=${1} SERVER="deploy@example.com" DEPLOY_DIR="/opt/${APP_NAME}" if [ -z "$BACKUP_TAG" ]; then echo "❌ Please specify a rollback version: ./rollback.sh <tag>" exit 1 fi ssh ${SERVER} << EOF cd ${DEPLOY_DIR} export TAG=${BACKUP_TAG} docker-compose pull docker-compose up -d sleep 10 docker-compose ps EOFTechnical Analysis
The rollback tag is read directly from the first command-line argument and interpolated without validation or shell-safe quoting into a heredoc processed by a remote shell.
Because
${BACKUP_TAG}becomes part of the remote command text, shell metacharacters such as semicolons, command substitutions, redirections, and newlines can change the intended command structure. For example, a tag containingv1; id; #would result in the injected command being evaluated by the remote shell.Quoting only the local variable assignment would not fully resolve the issue because the value is ultimately embedded in dynamically generated remote shell code. The value must be strictly validated and transmitted as data rather than executable syntax.
Attack Path
- An attacker gains control over, or convinces an operator to use, the rollback tag argument.
- The operator invokes the generated script with a malicious value, such as:
bash ./rollback.sh 'v1; malicious_command; #' - The value is inserted into the SSH heredoc:
bash export TAG=v1; malicious_command; # - SSH sends the generated command stream to the configured deployment server.
- The remote shell executes the injected command with the privileges of the deployment SSH account.
Impact Assessment
Successful e ...[truncated 536 chars]
- Remediation
View remediation
Remediation Suggestions
- Validate image tags against a strict allowlist before any network operation:
bash BACKUP_TAG=${1:-} if ! [[ "$BACKUP_TAG" =~ ^[A-Za-z0-9][A-Za-z0-9._-]{0,127}$ ]]; then printf 'Invalid rollback tag.\n' >&2 exit 1 fi - Validate fixed configuration values such as
SERVERandDEPLOY_DIRseparately. - Do not interpolate untrusted data directly into a heredoc containing remote commands.
- Pass the tag as a safely quoted positional argument to a fixed remote script, or deploy through an API that treats the tag as structured data.
- If shell transport is unavoidable, use robust shell escaping such as
printf '%q'after allowlist validation. - Restrict the deployment account to the minimum commands and directories required for deployment.
- Avoid granting the account unrestricted
sudoor general-purpose interactive shell access. - Record and alert on rollback operations so unexpected tags and commands can be investigated.
- Validate image tags against a strict allowlist before any network operation:
