T09 · Insecure Skill Coding Practices
- Location
sync.sh:13- Finding
Environment-Controlled rsync Operands Permit Option Injection
- Content
View full analysis
Vulnerability Details
File Location:
sync.sh, lines 13-26
Vulnerability Type: Improper neutralization of option-like path values
Risk Level: MediumVulnerable Code
bash CONFIG_SRC="${GOG_CONFIG_DIR:-$HOME/Games/GOG/config}" CONFIG_DST="${GOG_CONFIG_REMOTE:-user@remote:/backups/gog/config}" echo "Syncing GOG game custom configs from $CONFIG_SRC..." if [ ! -d "$CONFIG_SRC" ]; then echo "Config directory not found: $CONFIG_SRC" echo "Set GOG_CONFIG_DIR to your config path." exit 1 fi rsync -av --include='*/' --include='*.ini' --include='*.cfg' \ --include='*.json' --include='*.xml' --include='*.bind' \ --exclude='*' "$CONFIG_SRC/" "$CONFIG_DST/" echo "Config sync complete."Technical Analysis
The values of
GOG_CONFIG_DIRandGOG_CONFIG_REMOTEare supplied directly asrsynccommand-line operands. Shell quoting prevents word splitting and shell metacharacter expansion, but it does not preventrsyncfrom interpreting an argument beginning with-as an option.The source directory check only verifies that the supplied string identifies a directory. It does not reject option-shaped names. An attacker who can control the working directory and environment could create a directory whose name begins with an
rsyncoption and then assign that name toGOG_CONFIG_DIR.The unconditional trailing
/restricts which injected options can be used successfully, but options that accept directory-like values may still be parsed. At minimum, this can alter transfer behavior, cause the operation to fail, or prevent the intended backup. More severe effects depend on the installedrsyncversion and the specific option accepted.Attack Path
- Obtain control over the environment variables used to launch the Skill.
- Create an option-shaped directory that satisfies the
-dvalidation, such as a relative hierarchy whose first component begins with anrsyncoption.
...[truncated 795 chars]
- Remediation
View remediation
Remediation Suggestions
- Reject
GOG_CONFIG_DIRandGOG_CONFIG_REMOTEvalues that begin with-. - Canonicalize the local source with a trusted mechanism such as
realpathand require it to be an absolute directory under an approved root. - Validate remote destinations against a strict expected syntax or an allowlist of approved hosts and base paths.
- Use an explicit
--option terminator before path operands where supported by the deployedrsyncversion. - Keep transport-related options fixed in the script rather than allowing environment-controlled values to affect option parsing.
- Abort on transfer failures by checking the
rsyncexit status, preferably withset -euo pipefailand explicit error reporting. - Add tests covering values beginning with
-, embedded whitespace, remote-specifier characters, and unexpected path traversal.
- Reject
