T09 · Insecure Skill Coding Practices
- Location
src/backup_manager.js:154- Finding
Shell Command Injection Through Configuration and Restore Arguments
- Content
View full analysis
`--exclude "${pattern}"`) .join(' '); // Construir comando rClone - UN solo comando para todas las fuentes let command = `rclone sync \\\n`; if (incremental) { command += ` --backup-dir "${this.config.remote}:${this.config.basePath}/incremental-${backupDate}" \\\n`; } command += ` ${excludeArgs} \\\n`; command += ` --progress \\\n`; command += ` --log-file ${LOG_FILE} \\\n`; command += ` -L \\\n`; // Combinar todas las fuentes en un solo comando const allSources = this.config.sources.join(' '); command += ` ${allSources} \\\n`; command += ` "${this.config.remote}:${backupPath}"`; const { stdout, stderr } = await execAsync(command, { shell: true }); ``` The restore command also incorporates direct CLI input: ```javascript async function handleRestoreBackup(manager, args) { const backupName = args[0]; const targetPath = args[1] || '/tmp/restore-backup'; // ... const result = await manager.restoreBackup(backupName, targetPath); } ``` ```javascript const sourcePath = `${this.config.remote}:${this.config.basePath}/${backupName}`; const command = `rclone copy "${sourcePath}" "${targetPath}" --progress`; const startTime = Date.now(); const { stdout, stderr } = await execAsync(command, { shell: true }); ``` ### Technical Analysis The application constructs shell commands by interpolating values from `backup_config.json` and direct command-line arguments. It then executes the resulting strings using `child_process.exec` with `shell: true`. Quoting a value with double quotes does not make it safe for shell execution. An input containing an embedded double quote can terminate the quoted argument and ...[truncated 1784 chars]- Remediation
View remediation
