T09 · Insecure Skill Coding Practices
- Location
scripts/voice_handler.py:30- Finding
Shell and Python Code Injection Through Attacker-Controlled Audio Paths
- Content
View full analysis
/dev/null" subprocess.run(cmd, shell=True, check=True) audio_file = wav_file # Transcribe with faster-whisper cmd = [ sys.executable, "-c", """ from faster_whisper import WhisperModel import sys model = WhisperModel('%s', device='cpu', compute_type='int8') segments, info = model.transcribe('%s', beam_size=5) text = ' '.join(segment.text for segment in segments) print(json.dumps({'text': text, 'language': info.language, 'probability': info.language_probability})) """ % (self.stt_model, audio_file) ] ``` ### Technical Analysis The `audio_file` value is inserted directly into a shell command enclosed only by single quotation marks. A path containing a single quote can terminate the quoted argument and introduce additional shell syntax. The resulting string is then executed with `shell=True`, giving the shell an opportunity to interpret injected metacharacters and commands. The path is subsequently interpolated into Python source passed to `python -c`. Quoting the path inside the generated Python source does not make it safe: a path containing a quote, closing parenthesis, or newline can alter the resulting Python program. The vulnerable method is exposed through `VoiceHandler.audio_to_text()` and through the module's command-line entry point. Consequently, any integration that passes externally influenced attachment paths to this method may expose the process to code execution. ### Attack Path 1. An attacker causes an audio attachment or local file to be stored under a path containing shell or Python syntax. 2. OpenClaw or another integrat ...[truncated 919 chars]- Remediation
View remediation
