T07 · Tool Hijacking and Spoofing
- Location
scripts/main.py:53- Finding
Unverified Sibling Module Is Dynamically Executed
- Content
View full analysis
Vulnerability Details
File Location:
scripts/main.py, lines 53-59
Vulnerability Type: Untrusted local module loading and execution
Risk Level: HighVulnerable Code:
python def _load_engine(): """Charge rapprochement-paiements/scripts/main.py comme moteur partagé.""" engine_path = (Path(__file__).resolve().parents[2] / "rapprochement-paiements" / "scripts" / "main.py") spec = _ilu.spec_from_file_location("rappro_engine", str(engine_path)) mod = _ilu.module_from_spec(spec) spec.loader.exec_module(mod) return modTechnical Analysis
The reconciliation engine is loaded from a sibling directory outside the audited project package. The code does not verify the target file's ownership, permissions, expected version, cryptographic digest, or signature before calling
exec_module().Loading a Python module executes its top-level code immediately. Consequently, control of the sibling path is equivalent to control of executable code within this Skill. The path is predictable and resolved relative to the current Skill, making replacement or pre-positioning straightforward for a user, package, or process that can write to the common parent directory.
The implementation also assumes that the resolved import specification and loader are valid without checking either value. Although that can cause availability failures, the primary security issue is execution across an unverified local trust boundary.
Attack Path
- The attacker obtains write access to the common directory containing this Skill and the expected
rapprochement-paiementssibling directory. - The attacker creates or replaces
rapprochement-paiements/scripts/main.pywith a malicious Python module. - A user runs
scripts/main.pyafter all required sidecars are available. write_outputs()invokes_load_engine().spec.loader.exec_module(mod)executes the attacker's top- ...[truncated 728 chars]
- The attacker obtains write access to the common directory containing this Skill and the expected
- Remediation
View remediation
Remediation Suggestions
- Package the reconciliation engine as a reviewed, version-pinned dependency instead of executing a file from a mutable sibling directory.
- If external local loading is unavoidable, maintain an allowlisted cryptographic digest or signature and verify it before constructing the module specification.
- Resolve the path and verify that it remains beneath an explicitly trusted, administrator-controlled directory.
- Reject symbolic links and files writable by unauthorized users or groups.
- Validate that
specandspec.loaderare notNonebefore use. - Run the reconciliation component under a restricted account or sandbox with access only to the required client directory.
- Add a test proving that modified, unsigned, symlinked, or permission-unsafe engine files are rejected.
