T09 · Insecure Skill Coding Practices
- Location
vue-component-generator.sh:2- Finding
Arbitrary File Creation and Overwrite Through Unsanitized Component Name
- Content
View full analysis
"$NAME.vue" << 'VUE' ``` The generated file is subsequently used without path validation: ```bash sed -i "s/COMP_NAME/$NAME/g" "$NAME.vue" ``` ### Technical Analysis The first positional argument is assigned directly to `NAME` and used as a filesystem path. Quoting prevents shell word splitting, but it does not prevent absolute paths, directory separators, or traversal sequences such as `../`. The `cat > "$NAME.vue"` redirection creates the selected file or truncates it if it already exists. Consequently, an attacker who can influence the component name can select any writable path whose constructed name ends in `.vue`. For example, a name such as `../../target` causes the script to write to `../../target.vue`. An absolute value such as `/tmp/target` writes to `/tmp/target.vue`. If an attacker can pre-create a symbolic link with a `.vue` filename, shell redirection will normally follow that link, potentially allowing an arbitrary writable target without requiring the final target itself to have a `.vue` suffix. ### Attack Path 1. An attacker gains control over the component-name argument, such as through an automated agent request, wrapper script, CI parameter, or untrusted user input. 2. The attacker supplies a traversal or absolute path: ```bash ./vue-component-generator.sh ../../target ``` 3. The shell resolves `"$NAME.vue"` to `../../target.vue`. 4. The output redirection creates or truncates that file before writing the Vue template. 5. The subsequent `sed -i` operation modifies the same attacker-selected file. 6. Data in an existing writable file can therefore be destroyed or replaced under the invoking user's permissions. ### Impact Assessment The vulnerability permits creation, truncation, and ...[truncated 583 chars]- Remediation
View remediation
&2 exit 1 fi ``` 2. Reject path separators, traversal sequences, control characters, newlines, and names beginning with `-`. 3. If output-directory selection is required, accept it through a separate option and canonicalize it before use. 4. Verify that the resolved destination remains inside the authorized output directory. 5. Refuse to overwrite existing files unless an explicit trusted `--force` option is supplied: ```bash OUTPUT_FILE="$OUTPUT_DIR/$NAME.vue" if [[ -e "$OUTPUT_FILE" || -L "$OUTPUT_FILE" ]]; then printf 'Error: destination already exists\n' >&2 exit 1 fi ``` 6. Reject symbolic-link destinations and use safe file-creation semantics where possible. 7. Run the generator with the minimum filesystem permissions required. ]]>
