T09 · Insecure Skill Coding Practices
- Location
scripts/daily_health_report_pro.sh:46- Finding
Arbitrary Python Code Execution Through Unquoted Heredoc Interpolation
- Content
View full analysis
&1) echo "$result" >> "$LOG_FILE" # Extract the text report and PDF URL text_report=$(echo "$result" | sed -n '/=== TEXT_REPORT_START ===/,/=== TEXT_REPORT_END ===/p' | sed '1d;$d') pdf_url=$(echo "$result" | grep "=== PDF_URL ===" -A 1 | tail -1) if [ -z "$text_report" ] || [ -z "$pdf_url" ]; then echo "❌ 报告生成失败" >> "$LOG_FILE" exit 1 fi # Use Python to send to three channels python3 << PYTHON_SCRIPT import urllib.request import json import sys import os text_report = '''${text_report}''' pdf_url = '${pdf_url}' current_date = '${CURRENT_DATE}' ``` ### Technical Analysis The script captures report content derived from a local health-record Markdown file and directly interpolates that content into executable Python source inside an unquoted shell heredoc. The `text_report` variable is inserted between Python triple quotes without escaping Python delimiters, backslashes, or newline-sensitive syntax. An attacker-controlled value containing `'''` can close the intended string literal and append arbitrary Python statements. The resulting heredoc is then executed by `python3`. The report generator includes parsed food descriptions and other health-record-derived values in the generated text report. Therefore, an attacker who can influence the daily Markdown record can potentially propagate a malicious string into `text_report`. The `pdf_url` variable is similarly inserted into a single-quoted Python string without escaping, providing another possible injection surface if its source becomes attacker-controlled. ### Attack Path 1. An attacker gains the ability to modify or in ...[truncated 1708 chars]- Remediation
View remediation
