T09 · Insecure Skill Coding Practices
- Location
scripts/create-lxc.sh:34- Finding
Root-Level Remote Command Injection Through Unvalidated Arguments
- Content
View full analysis
/dev/null; pct destroy $ID --purge" elif [ "$TYPE" = "vm" ]; then ssh "$HOST" "qm stop $ID 2>/dev/null; qm destroy $ID --purge" ``` ```bash # scripts/find-ip.sh:11-14 if [ "$TYPE" = "lxc" ]; then IP=$(ssh "$HOST" "pct exec $ID -- hostname -I 2>/dev/null" | awk '{print $1}') elif [ "$TYPE" = "vm" ]; then IP=$(ssh "$HOST" "qm guest cmd $ID network-get-interfaces 2>/dev/null" | grep -oP '"ip-address"\s*:\s*"\K[0-9.]+' | head -1) ``` ```bash # scripts/post-boot-setup.sh:14-27 ssh "$HOST" "pct exec $CTID -- bash -c ' export DEBIAN_FRONTEND=noninteractive apt-get update -qq apt-get install -y -qq docker.io curl git htop $EXTRA '" ssh "$HOST" "pct exec $CTID -- bash -c ' systemctl enable docker systemctl start docker mkdir -p /usr/local/lib/docker/cli-plugins curl -SL https://github.com/docker/compose/releases/latest/download/docker-compose-linux-x86_64 -o /usr/local/lib/docker/cli-plugins/docker-compose chmod +x /usr/ ...[truncated 2597 chars]- Remediation
View remediation
