T09 · Insecure Skill Coding Practices
- Location
scripts/amap-proxy.js:17- Finding
Unauthenticated Shell Command Injection in the Amap Proxy
- Content
View full analysis
{ // ... }); } function handleDetail(poiId, response) { const amapMapsDir = path.join(__dirname, '..', '..', 'amap-maps'); const amapKey = process.env.AMAP_KEY || "88628414733cf2ccb7ce2f94cfd680ef"; const command = `cd "${amapMapsDir}" && AMAP_KEY="${amapKey}" node scripts/amap.js search detail "${poiId}"`; exec(command, { timeout: 10000 }, (error, stdout, stderr) => { // ... }); } ``` The affected values originate from HTTP request parameters: ```javascript const query = parsedUrl.query.q; const city = parsedUrl.query.city || '重庆'; // ... const poiId = pathname.split('/api/detail/')[1]; ``` The service is started without an explicit loopback address: ```javascript server.listen(PORT, () => { console.log(`AMap Search Proxy running on http://localhost:${PORT}`); }); ``` ### Technical Analysis The `query`, `city`, and `poiId` values are attacker-controlled and are interpolated into shell command strings passed to `child_process.exec`. Because `exec` invokes a shell, metacharacters such as quotes, command separators, command substitutions, and redirection operators are interpreted by the operating system. Placing `query` inside double quotes does not make it safe. An attacker can inject a closing quote or use shell substitut ...[truncated 1219 chars]- Remediation
View remediation
