T09 · Insecure Skill Coding Practices
- Location
scripts/zoom.py:28- Finding
OAuth Bearer Token Stored in an Unsafe Predictable Temporary File
- Content
View full analysis
time.time() + 60: return cached["access_token"] except (json.JSONDecodeError, KeyError): pass ``` ```python with open(TOKEN_CACHE, "w") as f: json.dump(data, f) ``` ### Technical Analysis The application stores a reusable Zoom OAuth access token in the fixed, globally predictable path `/tmp/zoom_token.json`. The file is opened using ordinary Python file operations without: - Explicitly setting permissions to `0600` - Atomically creating the file with exclusive access - Verifying that the path is a regular file - Verifying file ownership - Rejecting symbolic links - Using a private per-user runtime directory The actual permissions therefore depend on the process umask. In a multi-user environment, another local user may be able to read the cached token. The separate existence check followed by `open()` also introduces a time-of-check/time-of-use condition. Because the destination is predictable, a local attacker may pre-create `/tmp/zoom_token.json` as a symbolic link. When the victim runs the CLI and a new token is obtained, the application follows that link and writes JSON token data to the linked destination, provided the victim has permission to write there. The cached response may contain fields beyond the access token, since the complete OAuth response is written to disk after adding `expires_at`. ### Attack Path 1. An attacker with local access predicts the fixed cache path `/tmp/zoom_token.json`. 2. The attacker either monitors or reads a cache created with permissive effective permissio ...[truncated 1185 chars]- Remediation
View remediation
