T09 · Insecure Skill Coding Practices
- Location
scripts/load_dolphindb_env.sh:9- Finding
Shell Command Injection Through Evaluation of Unsafely Serialized Environment Data
- Content
View full analysis
/dev/null)" ``` `scripts/detect_dolphindb_env.sh:12-14`: ```bash while IFS= read -r line; do ENV_NAME=$(echo "$line" | awk '{print $1}') ENV_PATH=$(echo "$line" | awk '{print $NF}') ``` `scripts/detect_dolphindb_env.sh:83-86`: ```bash echo "export DOLPHINDB_PYTHON_BIN=\"$DOLPHINDB_PYTHON\"" echo "export DOLPHINDB_SDK_VERSION=\"$DOLPHINDB_VERSION\"" echo "export DOLPHINDB_PYTHON_VER=\"$PYTHON_VER\"" echo "export DOLPHINDB_ENV_PATH=\"$ENV_PATH\"" ``` ### Technical Analysis The loader executes all standard output generated by `detect_dolphindb_env.sh` as shell source through `eval`. The detector constructs that output by interpolating values obtained from Conda environment records and executable output into double-quoted shell assignments. Double quotes around the emitted values do not provide safe serialization. A value containing a double quote, command substitution, semicolon, newline, or another shell metacharacter can alter the generated assignment. When the loader subsequently passes the generated text to `eval`, the shell parses those characters as executable syntax. For example, a literal path component containing `$(command)` can be emitted inside the generated assignment. The command substitution is not executed during ordinary variable expansion in the detector, but it becomes active shell syntax during the second parse performed by `eval`. The same unsafe serialization pattern affects the Python path, SDK version, Python vers ...[truncated 1347 chars]- Remediation
View remediation
/dev/null`, because doing so can conceal malformed output and complicate incident diagnosis. ]]>
