T09 · Insecure Skill Coding Practices
- Location
build.sh:11- Finding
PowerShell Command Injection Through Unvalidated Version Argument
- Content
View full analysis
/dev/null 2>&1 || command -v powershell >/dev/null 2>&1; then PSH="$(command -v powershell.exe 2>/dev/null || command -v powershell)" WIN_SRC="$(cygpath -w "$STAGE_DIR" 2>/dev/null || echo "$STAGE_DIR")" WIN_OUT="$(cygpath -w "$OUT_DIR/$ZIP_NAME" 2>/dev/null || echo "$OUT_DIR/$ZIP_NAME")" "$PSH" -NoProfile -Command "Compress-Archive -Path '${WIN_SRC}' -DestinationPath '${WIN_OUT}' -Force" echo " packed via: powershell Compress-Archive" ``` The same unsafe construction is also used by the `Expand-Archive` PowerShell fallback on line 43: ```bash "$PSH2" -NoProfile -Command "Expand-Archive -Path '${WIN_ZIP}' -DestinationPath '${WIN_DEST}' -Force" ``` ### Technical Analysis The first positional argument is assigned directly to `VER` without format validation. This value is subsequently embedded in directory and ZIP names and therefore reaches `WIN_SRC`, `WIN_OUT`, and `WIN_ZIP`. These paths are interpolated into textual PowerShell programs passed through `powershell -Command`. Although Bash quotes the overall command argument, the attacker-controlled values are placed inside PowerShell single-quoted string literals. A version containing a single quote followed by PowerShell syntax can terminate the intended string literal, introduce an additional statement, and comment out or otherwise neutralize the remaining text. Bash argument quoting only protects the transi ...[truncated 1972 chars]- Remediation
View remediation
