T03 · Remote Payload Retrieval and Execution
- Location
references/seedance-specs.md:105- Finding
Unverified Remote Installer Is Executed Directly by a Shell
- Content
View full analysis
Vulnerability Details
File Location:
references/seedance-specs.md, lines 105-111
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code
markdown ## 即梦 CLI 联动指南(v1.8.4 新增) > 当 Shot Design 部署在支持 CLI 调用的 Agent 环境中(如 OpenClaw + Dreamina CLI),提示词可以直接通过 CLI 提交生成。本节提供命令映射速查。 ### CLI 安装 ```bash curl -fsSL https://jimeng.jianying.com/cli | bash dreamina login # 首次登录text ### Technical Analysis The installation instruction downloads a mutable response from `https://jimeng.jianying.com/cli` and passes it directly to `bash`. There is no version pinning, checksum validation, publisher-signature verification, local inspection step, or documented description of the installer’s expected behavior. HTTPS protects transport integrity when the endpoint and certificate infrastructure remain trustworthy, but it does not establish that the remote script is safe or immutable. If the endpoint, hosting account, deployment pipeline, DNS/TLS infrastructure, or upstream content is compromised, arbitrary replacement commands would be executed immediately. The Skill’s principal declared function is to produce structured video prompts. Installing a remote CLI is optional and is not necessary for that core function. Moreover, `SKILL.md` declares `execution: none`, but its semantic routing directs users interested in CLI or local generation to this reference. The command therefore introduces a local code-execution path beyond the minimum privileges required for prompt design. No evidence in the audited package establishes the contents or trustworthiness of the remote installer. This finding concerns the unsafe installation mechanism; it does not assert that the current remote response is malicious. ### Attack Path 1. A user requests CLI integration, command-line operation, or local video generation. 2. The routing rule in `SKILL.md` directs the Agent or user to the CLI integration section of `references/seedance-s ...[truncated 1395 chars]- Remediation
View remediation
Remediation Suggestions
-
Remove the direct
curl | bashpipeline. -
Distribute the CLI through a documented, versioned official release channel or a trusted package repository.
-
Pin installation instructions to an explicit version rather than a mutable endpoint.
-
Download the artifact as a separate step so users can inspect it before execution.
-
Publish and require verification of a cryptographic publisher signature. If signatures are unavailable, provide a SHA-256 checksum over a versioned immutable artifact.
-
Use an installation flow similar to:
bash curl --fail --show-error --location \ --output dreamina-installer-vX.Y.Z.sh \ https://example.invalid/releases/vX.Y.Z/dreamina-installer.sh echo "<PINNED_SHA256> dreamina-installer-vX.Y.Z.sh" | sha256sum --check less dreamina-installer-vX.Y.Z.sh bash dreamina-installer-vX.Y.Z.sh -
Replace the placeholder URL and checksum above only with an authenticated, immutable official release and its independently published checksum or signature.
-
Document files, directories, credentials, network endpoints, and permissions used by the installer.
-
Explicitly prohibit Agents from automatically installing or executing the CLI. Require informed user confirmation before any download or execution.
-
Run the CLI with ordinary user privileges and never recommend
sudounless a narrowly scoped, documented operation genuinely requires it. -
Keep prompt generation independent of CLI installation so the Skill retains its instruction-only, least-privilege operation.
-
