T09 · Insecure Skill Coding Practices
- Location
src/wordpress.py:18- Finding
Root-Capable OS Command Injection Through Shell-Interpolated Inputs
- Content
View full analysis
tuple[str, str, int]: """Execute command locally through subprocess or remotely through SSH.""" if self.ssh_host == "localhost" or self.ssh_host in ("127.0.0.1", ""): # Local mode: execute directly result = subprocess.run( cmd, shell=True, capture_output=True, text=True, timeout=60 ) return result.stdout.strip(), result.stderr.strip(), result.returncode else: # Remote mode: execute through SSH full_cmd = f"cd {self.web_root} && {cmd}" result = subprocess.run( ["ssh", "-i", self.ssh_key, "-o", "StrictHostKeyChecking=no", f"{self.ssh_user}@{self.ssh_host}", full_cmd], capture_output=True, text=True, timeout=60 ) return result.stdout.strip(), result.stderr.strip(), result.returncode def _wp(self, args: str) -> tuple[str, str, int]: """Execute WP-CLI command.""" return self._ssh( f"WP_CLI_PHP={self.php_bin} /usr/local/bin/wp " f"--allow-root --path={self.web_root} {args}" ) ``` Additional affected construction in `src/seo.py`: ```python def _wp(self, args: str) -> Tuple[str, str, int]: """Execute WP-CLI command.""" if not self.wp_web_root: return "", "No web root configured", 1 cmd = ( f"cd {self.wp_web_root} && " f"WP_CLI_PHP={self.php_bin} " f"{self.wp_cli} --allow-root {args}" ) r = subprocess.run( cmd, shell=True, capture_output=True, text=True, timeout=60 ) return r.stdout.strip(), r.std ...[truncated 2561 chars]- Remediation
View remediation
