T09 · Insecure Skill Coding Practices
- Location
lib/bw-functions.sh:15- Finding
Arbitrary Shell Command Execution Through Bitwarden Secure Notes
- Content
View full analysis
`. 4. `bw get item` returns the attacker-controlled note. 5. `jq` extracts the note without neutralizing shell syntax. 6. `eval` executes the note with the privileges and environment of the victim's current shell. ### Impact Assessment Successful exploitation permits arbitrary command execution with the privileges of the user who sourced the functions. The injected command could: - Read environment variables and secrets already loaded into the shell. - Access the unlocked Bitwarden CLI session through `BW_SESSION`. - Retrieve additional vault records available to the victim. - Read, modify, or delete fil ...[truncated 268 chars]- Remediation
View remediation
