T09 · Insecure Skill Coding Practices
- Location
skill.py:8- Finding
MATLAB Code Injection Through Unescaped Input Paths
- Content
View full analysis
Vulnerability Details
File Location:
skill.py, lines 8–15
Vulnerability Type: MATLAB code injection caused by unsafe string interpolation
Risk Level: HighVulnerable Code
python matlab_script = f""" addpath('matlab'); brain_as_analysis('{lh_path}', '{rh_path}', '{out_dir}'); exit; """ subprocess.run([ "matlab", "-batch", matlab_script ])Technical Analysis
The caller-controlled
lh_pathandrh_pathvalues are interpolated directly into executable MATLAB source as single-quoted string literals. Neither value is validated nor escaped before the generated source is passed to MATLAB through its-batchoption.Although
subprocess.runuses an argument list and therefore avoids command interpretation by a system shell at the Python layer, it does not protect against injection into the MATLAB language itself. An attacker can place a single quote in either path to terminate the intended MATLAB string and append arbitrary MATLAB statements. MATLAB provides functions capable of executing operating-system commands, so successful MATLAB code injection can become arbitrary command execution under the account running the skill.Attack Path
- An attacker supplies a crafted value for
lh_pathorrh_path. - The crafted path contains a single quote that closes the surrounding MATLAB string literal.
- The remaining characters introduce attacker-selected MATLAB statements and neutralize or accommodate the original trailing syntax.
- Python constructs
matlab_scriptcontaining the injected statements. subprocess.runlaunchesmatlab -batchwith that script.- MATLAB evaluates the injected code with the privileges of the skill process.
- The injected MATLAB code can invoke operating-system commands or access files available to that process.
Impact Assessment
Successful exploitation permits arbitrary MATLAB code execution and potentially arbitrary operating ...[truncated 591 chars]
- An attacker supplies a crafted value for
- Remediation
View remediation
Remediation Suggestions
- Avoid generating MATLAB source code from caller-controlled values. Transfer file paths through a non-code parameter mechanism, such as environment variables that MATLAB reads with
getenv, or a securely created data/configuration file. - If source interpolation cannot be eliminated, encode MATLAB string literals correctly by replacing every single quote with two single quotes. Also reject null bytes, line breaks, and other unexpected control characters. Escaping should be treated as defense in depth rather than the primary control.
- Resolve both inputs to canonical absolute paths and verify that each points to an expected regular file within an explicitly approved upload directory.
- Enforce the expected FreeSurfer filenames or extensions and reject inputs containing unsupported characters or path traversal components.
- Generate the output directory beneath a fixed, trusted base directory and use absolute paths when invoking MATLAB.
- Run MATLAB using a dedicated, minimally privileged account with narrowly scoped filesystem access and restricted network access.
- Invoke
subprocess.run(..., check=True)and handle failures explicitly so unsuccessful or malformed analysis runs are not reported as valid results. - Add security tests using paths containing quotes, semicolons, line breaks, traversal sequences, and other MATLAB metacharacters to verify that they are rejected or passed only as inert data.
- Avoid generating MATLAB source code from caller-controlled values. Transfer file paths through a non-code parameter mechanism, such as environment variables that MATLAB reads with
