T09 · Insecure Skill Coding Practices
- Location
scripts/apply.sh:105- Finding
Inline Patch Removal Can Truncate the Control UI HTML
- Content
View full analysis
/ { buf=$0; in_script=1; next } in_script { buf=buf"\n"$0 if (index($0, marker)) { has_marker=1 } if ($0 ~ /<\/script>/) { if (!has_marker) print buf buf=""; in_script=0; has_marker=0 } next } { print } ' "$INDEX_FILE" > "${INDEX_FILE}.tmp" && mv "${INDEX_FILE}.tmp" "$INDEX_FILE" ``` ### Technical Analysis The fallback uninstall implementation attempts to parse HTML scripts with line-oriented AWK rules. When a line contains both ``, the opening-tag rule stores the line and immediately executes `next`: ```awk /`, the buffered content is discarded at end-of-file. The generated output is not validated for completeness before: ```bash mv "${INDEX_FILE}.tmp" "$INDEX_FILE" ``` This behavior is particularly relevant to bundled or minified HTML, where complete script elements commonly appear on one line. It can replace the original Control UI file with a truncated document. ### Attack Path 1. The target Control UI `index.html` contains the patch marker. 2. The corresponding `.bak` file is absent, causing uninstall to use the AWK fallback. 3. The HTML contains a one-line script element with both opening and closing tags. 4. The user executes: ```bash bash scripts/apply.sh --uninstall ``` 5. AWK sees `- Remediation
View remediation
``` 2. Remove only the content between those exact markers rather than attempting to parse arbitrary HTML script elements with AWK. 3. Create temporary files with `mktemp` in the destination directory instead of using a predictable `${INDEX_FILE}.tmp` path. 4. Before replacement, validate that: - Both expected patch delimiters were found. - The output still contains required document structure such as `` and ``. - The output is nonempty and does not unexpectedly shrink beyond the known patch size. - The patch marker is absent after removal. 5. Preserve the original file until all validation succeeds, then perform a same-filesystem atomic rename. 6. If validation fails, leave the target untouched and return a nonzero exit status. ]]>
