T09 · Insecure Skill Coding Practices
- Location
scripts/zoom_meeting.sh:34- Finding
Unsafe JSON Construction Allows Request-Body Injection
- Content
View full analysis
Join Zoom Meeting:
${JOIN_URL}\" } }") ``` ### Technical Analysis The script constructs JSON by directly interpolating command-line arguments, environment variables, and API response values into double-quoted shell strings. These values are not JSON-encoded before insertion. In particular: - `TOPIC` can contain quotation marks, backslashes, control characters, or additional ...[truncated 2566 chars]- Remediation
View remediation
1440 )); then echo "ERROR: Duration must be an integer between 1 and 1440" >&2 exit 1 fi if ! [[ "$START_TIME" =~ ^[0-9]{4}-[0-9]{2}-[0-9]{2}T[0-9]{2}:[0-9]{2}:[0-9]{2}$ ]]; then echo "ERROR: Invalid start_time format" >&2 exit 1 fi ZOOM_BODY=$(jq -n \ --arg topic "$TOPIC" \ --arg start_time "$START_TIME" \ --argjson duration "$DURATION" \ '{ topic: $topic, type: 2, start_time: $start_time, duration: $duration, timezone: "Asia/Jerusalem", settings: { host_video: true, participant_video: true, join_before_host: true } }') ``` 2. Pass the generated body using `curl --data-binary "$ZOOM_BODY"`. 3. Build the Google Calendar patch with `jq -n --arg` for every interpolated string. 4. Validate `EVENT_ID` against the expected Google Calendar event-ID character set before placing it in the URL, and URL-encode it defensively. 5. Check HTTP status codes with `curl --fail-with-body` rather than relying exclusively on selected JSON fields. 6. Consider compensating cleanup, such as deleting the newly created Zoom meeting, when the calendar update fails. ]]>
