T09 · Insecure Skill Coding Practices
- Location
scripts/schema-export.sh:8- Finding
Unvalidated Output Path Enables Path Traversal and Symlink-Based File Clobbering
- Content
View full analysis
[org-alias]}" ORG="${2:-}" ORG_FLAG="" if [ -n "$ORG" ]; then ORG_FLAG="--target-org $ORG" fi OUTPUT_FILE="${OBJECT}_schema.md" echo "# $OBJECT Schema" > "$OUTPUT_FILE" echo "" >> "$OUTPUT_FILE" echo "Generated: $(date)" >> "$OUTPUT_FILE" echo "" >> "$OUTPUT_FILE" echo "## Fields" >> "$OUTPUT_FILE" echo "" >> "$OUTPUT_FILE" echo "| API Name | Label | Type | Required |" >> "$OUTPUT_FILE" echo "|----------|-------|------|----------|" >> "$OUTPUT_FILE" sf sobject describe --sobject "$OBJECT" $ORG_FLAG --json 2>/dev/null | \ jq -r '.result.fields[] | "| \(.name) | \(.label) | \(.type) | \(.nillable | not) |"' >> "$OUTPUT_FILE" echo "" >> "$OUTPUT_FILE" echo "## Record Types" >> "$OUTPUT_FILE" echo "" >> "$OUTPUT_FILE" sf sobject describe --sobject "$OBJECT" $ORG_FLAG --json 2>/dev/null | \ jq -r '.result.recordTypeInfos[] | "- \(.name) (\(.developerName))"' >> "$OUTPUT_FILE" 2>/dev/null || echo "- (none)" >> "$OUTPUT_FILE" ``` ### Technical Analysis The script accepts the `OBJECT` argument without validating that it is a legitimate Salesforce object identifier. It then directly incorporates that value into a filesystem path: ```bash OUTPUT_FILE="${OBJECT}_schema.md" ``` Shell redirections subsequently open this attacker-influenced path with truncation or append semantics. Directory traversal sequences such as `../` are preserved, allowing the output to escape the intended working directory. Direct traversal-based overwriting is constrained to paths representable with the appended `_schema.md` suffix. The output filename is also predictable, and the script neither rejects symbolic links nor creates the destination securely. If an attacker who can write to the execution directory c ...[truncated 2216 chars]- Remediation
View remediation
&2 exit 1 fi ``` 2. **Use a dedicated export directory.** Resolve all generated files beneath a controlled directory rather than the caller's current directory: ```bash EXPORT_DIR="${EXPORT_DIR:-./schema-exports}" mkdir -p -- "$EXPORT_DIR" OUTPUT_FILE="$EXPORT_DIR/${OBJECT}_schema.md" ``` 3. **Reject symbolic-link destinations and avoid overwriting existing files.** Create a new temporary file securely, write all content to it, and atomically rename it only after successful generation. Verify that the final destination is not a symbolic link and apply an explicit overwrite policy. 4. **Set restrictive file permissions.** Use an appropriate `umask`, such as: ```bash umask 077 ``` 5. **Write output only after successful Salesforce processing.** Capture and validate the `sf` and `jq` output before creating or replacing the destination file. This prevents invalid object names or failed API requests from leaving a truncated file. 6. **Represent optional CLI arguments with a Bash array.** Although not the primary file-clobbering flaw, this avoids word splitting and accidental injection of additional CLI options through the org alias: ```bash ORG_FLAG=() if [[ -n "$ORG" ]]; then ORG_FLAG=(--target-org "$ORG") fi sf sobject describe --sobject "$OBJECT" "${ORG_FLAG[@]}" --json ``` ]]>
