T09 · Insecure Skill Coding Practices
- Location
scripts/record-demo.mjs:137- Finding
Shell Command Injection Through Customizable Scene and Configuration Values
- Content
View full analysis
/dev/null`); execSync(`ffmpeg -y -i ${workDir}/${s.id}_video.mp4 -i ${audioDir}/${s.id}.mp3 -c:v copy -c:a aac -b:a 128k -shortest ${workDir}/${s.id}_final.mp4 2>/dev/null`); execSync(`ffmpeg -y -i ${workDir}/${s.id}_final.mp4 -c:v libx264 -preset slow -crf ${crf} -pix_fmt yuv420p -r ${outputFps} -c:a aac -b:a 128k -ar 44100 -ac 2 ${workDir}/${s.id}_norm.mp4 2>/dev/null`); ``` ```javascript execSync(`ffmpeg -y -f concat -safe 0 -i ${workDir}/concat.txt -c copy ${outputPath} 2>/dev/null`); ``` ### Technical Analysis The script constructs shell command strings by directly interpolating customizable scene and configuration values. Affected values include scene narration, scene IDs, working-directory paths, voice configuration, and the output path. Escaping only double quotation marks in `s.narration` is insufficient. Shell constructs such as command substitution—`$(...)` and backticks—are still evaluated inside double-quoted shell strings. Other interpolated values are not quoted or validated at all, allowing whitespace and shell metacharacters to alter command structure. Because `execSync()` receives a string, Node.js executes it through a shell. The shell interprets attacker-controlled syntax before invoking ` ...[truncated 1477 chars]- Remediation
View remediation
