T09 · Insecure Skill Coding Practices
- Location
scripts/clean-cache.sh:54- Finding
Arbitrary Command Execution Through Target Directory Path Injection
- Content
View full analysis
/dev/null" || true) ``` ### Technical Analysis The script accepts a user-controlled target directory and resolves it to an absolute path. Although the path is quoted when initially passed to `cd`, resolving it with `pwd` does not remove shell metacharacters from directory names. The resolved path is subsequently interpolated into a command string passed to `eval`. `eval` causes the shell to parse the generated string again. A valid directory name containing a double quote and additional shell syntax can therefore terminate the intended quoted argument and introduce arbitrary commands. For example, a directory path conceptually containing syntax such as: ```text /tmp/cache"; attacker_command; # ``` can transform the generated command into the equivalent of: ```bash find "/tmp/cache"; attacker_command; #" -name .build -type d ... -print0 ``` The injected command is then executed by the shell. The vulnerability is reachable during the scanning phase, so using `--dry-run` does not prevent exploitation. It is also reached before the cleanup confirmation prompt. The hard-coded `find_args` values are not themselves attacker-controlled, but that does not protect the separately interpolated `TARGET_DIR`. ### Attack Path 1. An attacker creates or controls a directory whose name contains shell metacharacters that break out of the double-quoted `find` argument. 2. The attacker persuades a user or agent to scan that directory, or supplies it as the requested project directory. 3. The script successfully ...[truncated 1216 chars]- Remediation
View remediation
/dev/null || true) ``` Because each cache pattern uses different predicates, define each expression as an array or implement a dedicated function for each supported cache type. Do not store executable shell fragments in strings. Additional hardening should include: 1. Validate that the resolved target is an existing directory. 2. Keep `--` separators where supported when passing potentially attacker-controlled paths to utilities. 3. Avoid command-string construction for all filesystem operations. 4. Add automated regression tests using target paths containing spaces, quotes, semicolons, dollar signs, command-substitution syntax, glob characters, leading hyphens, and newlines. 5. Verify in tests that neither normal scans nor `--dry-run` execute pathname contents as commands. 6. Consider refusing especially dangerous cleanup targets such as `/`, the user’s home directory, or other broad system locations unless explicitly supported and separately confirmed. ]]>
