T09 · Insecure Skill Coding Practices
- Location
scripts/inventory.py:396- Finding
Shell Command Injection in Generated QR Code Command
- Content
View full analysis
Vulnerability Details
File Location:
scripts/inventory.py, lines 396–400
Vulnerability Type: Shell command injection through unsafe command generation
Risk Level: MediumVulnerable Code
python # QR-friendly compact summary (single line, pipe-delimited) names = "|".join(i["name"] for i in box_items) qr_data = f"BOX:{box_id}|N:{len(box_items)}|V:{total:.0f}|{names}" print(f"\nQR data (compact):") print(f" {qr_data}") print(f"\n Tip: pipe this string into any QR code generator:") print(f" echo '{qr_data}' | qrencode -o {box_id}.png")Technical Analysis
The generated shell command incorporates
box_idand inventory item names without shell-safe escaping:box_idoriginates from the positionalbox-manifestargument.namescontains item names previously supplied through theaddcommand.qr_datacombines both values and is enclosed only in literal single quotes.box_idis also inserted unquoted into the output filename.
A single quote in an item name can terminate the intended quoted string. Shell metacharacters or command substitutions in either value can then introduce additional commands when the displayed recommendation is copied into a shell. The Python application does not execute the command directly, but it explicitly presents the command as a usage recommendation, making copied execution a credible attack path.
Attack Path
-
An attacker causes a crafted item name or box identifier containing shell syntax to be added to the inventory.
-
The crafted item is assigned to the maliciously named box.
-
A victim runs
box-manifestfor that box. -
The application generates a command resembling:
bash echo 'ATTACKER_CONTROLLED_DATA' | qrencode -o ATTACKER_CONTROLLED_BOX.png -
The victim follows the displayed tip and copies the command into a shell.
-
The shell interprets the injected syntax, executi ...[truncated 595 chars]
- Remediation
View remediation
Remediation Suggestions
-
Avoid presenting executable shell commands assembled from untrusted inventory data.
-
Prefer generating the QR image directly through a Python library or a subprocess call that uses an argument list with
shell=False. -
If a shell command must be displayed, escape every dynamic shell argument with
shlex.quote():python import shlex safe_data = shlex.quote(qr_data) safe_output = shlex.quote(f"{box_id}.png") print(f" printf '%s' {safe_data} | qrencode -o {safe_output}") -
Apply strict validation to box identifiers, such as
^[A-Za-z0-9_-]+$, and reject invalid identifiers. -
Do not rely exclusively on validation for QR content because item names may legitimately contain punctuation; use context-appropriate shell escaping.
-
Add tests containing single quotes, command substitutions, semicolons, pipes, newlines, leading hyphens, and other shell-significant input.
-
