T09 · Insecure Skill Coding Practices
- Location
scripts/script.sh:57- Finding
Unescaped User Input Produces Unsafe JSON and CSV Exports
- Content
View full analysis
Vulnerability Details
File Location:
scripts/script.sh, lines 57-79
Vulnerability Type: Improper output encoding and spreadsheet formula injection
Risk Level: MediumVulnerable Code
bash case "$fmt" in json) echo "[" > "$out" local first=1 for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do [ $first -eq 1 ] && first=0 || echo "," >> "$out" printf ' {"type":"%s","time":"%s","value":"%s"}' "$name" "$ts" "$val" >> "$out" done < "$f" done echo "\n]" >> "$out" ;; csv) echo "type,time,value" > "$out" for f in "$DATA_DIR"/*.log; do [ -f "$f" ] || continue local name=$(basename "$f" .log) while IFS='|' read -r ts val; do echo "$name,$ts,$val" >> "$out"; done < "$f" done ;;Technical Analysis
Maintenance entry values originate from command-line input and are stored without validation. The export implementation subsequently inserts these values directly into JSON and CSV output.
The JSON exporter does not escape quotation marks, backslashes, control characters, or embedded newlines. A value containing characters such as
"can terminate the intended JSON string and inject additional JSON properties or otherwise make the export invalid.The CSV exporter does not apply RFC 4180 quoting. Commas and newlines can create additional cells or records. A value beginning with spreadsheet formula indicators such as
=,+,-, or@may be interpreted as a formula when the resulting CSV file is opened in spreadsheet software.Attack Path
- An attacker supplies or persuades the user to record a crafted maintenance entry containing JSON metacharacters or a spreadsheet formula.
- The ...[truncated 1130 chars]
- Remediation
View remediation
Remediation Suggestions
- Generate JSON with a dedicated serializer rather than string interpolation. For example, use
jq -n --argfor each field so quotation marks, backslashes, and control characters are escaped correctly. - Generate CSV using an implementation that applies RFC 4180 encoding: enclose every field in double quotes and replace each embedded double quote with two double quotes.
- If exports are expected to be opened in spreadsheet applications, neutralize formula-leading cells according to the target application's guidance, such as prefixing dangerous values with an apostrophe after documenting this transformation.
- Add regression tests covering quotation marks, commas, backslashes, CR/LF characters, Unicode, and values beginning with
=,+,-, or@. - Validate generated JSON with a parser and generated CSV with a standards-compliant CSV reader before reporting a successful export.
- Generate JSON with a dedicated serializer rather than string interpolation. For example, use
