T05 · Unauthorized Access and Privilege Escalation
- Location
search.ts:77- Finding
Claude CLI Executes Without Permission Checks and Inherits the Entire Parent Environment
- Content
View full analysis
Vulnerability Details
File Location:
search.ts, lines 77–85
Vulnerability Type: Least-privilege violation and excessive environment exposure
Risk Level: HighVulnerable Code
typescript const isRoot = process.getuid?.() === 0; const args = ["--print", ...(isRoot ? [] : ["--dangerously-skip-permissions"]), "-p", prompt]; return new Promise((resolve) => { let output = ""; let errorOutput = ""; const proc = spawn(claudePath, args, { timeout, env: { ...process.env }, stdio: ["pipe", "pipe", "pipe"], });Technical Analysis
For non-root users, the code starts Claude CLI with
--dangerously-skip-permissions. This disables the CLI's normal interactive permission boundaries even though the skill's legitimate purpose only requires web research.The same subprocess receives a complete copy of
process.env. Consequently, the process can access not only the documentedCLAUDE_CODE_OAUTH_TOKEN, but also any unrelated credentials, API keys, cloud tokens, database connection strings, or other sensitive values inherited from the parent agent.This creates a dangerous combination:
- The research prompt contains caller-controlled
querycontent. - Web research can introduce untrusted instructions from retrieved pages.
- Claude CLI is invoked without its standard permission checks.
- The subprocess possesses every inherited environment variable.
Exploitability and the exact resources reachable depend on the tools and capabilities available to the installed Claude CLI. Nevertheless, the implementation unnecessarily removes a security boundary and grants access beyond the stated research task.
Attack Path
- An attacker supplies a crafted research query or publishes malicious instructions on a page likely to be returned during research.
- The untrusted content is incorporated into or processed during the Claude CLI session.
- The skill starts Claude C ...[truncated 1157 chars]
- The research prompt contains caller-controlled
- Remediation
View remediation
Remediation Suggestions
-
Remove
--dangerously-skip-permissionsand preserve Claude CLI's normal permission enforcement. -
If supported, explicitly allow only the web-search capabilities required by the skill and deny local filesystem, shell, and unrelated network tools.
-
Replace full environment inheritance with an explicit allowlist, for example:
typescript const childEnv: NodeJS.ProcessEnv = { PATH: process.env.PATH, HOME: process.env.HOME, CLAUDE_CODE_OAUTH_TOKEN: process.env.CLAUDE_CODE_OAUTH_TOKEN, }; const proc = spawn(claudePath, ["--print", "-p", prompt], { timeout, env: childEnv, stdio: ["pipe", "pipe", "pipe"], }); -
Validate that
CLAUDE_CODE_OAUTH_TOKENexists before execution and avoid passing unrelated environment variables. -
Run the subprocess in a sandbox with restricted filesystem and network access.
-
Clearly separate untrusted query text from trusted instructions and tell the downstream model not to follow instructions embedded in search queries or retrieved pages.
-
Document the actual subprocess permissions and exposed environment rather than implying that inheritance is limited to the OAuth token.
-
