T09 · Insecure Skill Coding Practices
- Location
scripts/tts.sh:123- Finding
Unvalidated Parameters Permit ComfyUI Workflow JSON Injection
- Content
View full analysis
Vulnerability Details
File Location:
scripts/tts.sh, lines 123-171
Vulnerability Type: Unvalidated JSON injection
Risk Level: MediumThe script directly interpolates command-line arguments and environment-derived values into a JSON heredoc. Unlike
TEXT, which is serialized withjq -R, the character, style, model, and sampling parameters are not safely encoded or validated.bash WORKFLOW=$(cat <<EOF { "10": { "inputs": { "character": "${CHARACTER}", "style": "${STYLE}", "custom_instruct": "" }, "class_type": "AILab_Qwen3TTSVoiceInstruct", "_meta": { "title": "Voice Instruct (QwenTTS)" } }, "11": { "inputs": { "filename_prefix": "audio/ComfyUI", "audioUI": "", "audio": [ "15", 0 ] }, "class_type": "SaveAudio", "_meta": { "title": "保存音频" } }, "12": { "inputs": { "audioUI": "", "audio": [ "15", 0 ] }, "class_type": "PreviewAudio", "_meta": { "title": "预览音频" } }, "14": { "inputs": { "preview": "", "previewMode": null, "source": [ "10", 0 ] }, "class_type": "PreviewAny", "_meta": { "title": "预览任意" } }, "15": { "inputs": { "text": $(echo "$TEXT" | jq -R .), "instruct": [ "10", 0 ], "model_size": "${MODEL_SIZE}", "device": "auto", "precision": "bf16", "language": "Auto", "max_new_tokens": 2048, "do_sample": false, "top_p": ${TOP_P}, "top_k": ${TOP_K}, "temperature": ${TEMPERATURE},Technical Analysis
Values assigned through
--character,--style,--model,--temperature,--top-p, and--top-k, or their correspondingTTS_*env ...[truncated 2109 chars]- Remediation
View remediation
Remediation Suggestions
- Construct the complete workflow and request payload with
jqrather than a shell heredoc. - Pass strings with
jq --argso quotation marks, backslashes, and control characters are serialized safely. - Validate numeric options with strict regular expressions and range checks before using
jq --argjson. - Allow-list supported model sizes such as
0.5B,1.7B, and3B. - Allow-list supported character and style identifiers if the valid values are known.
- Reject non-finite values, JSON fragments, unexpected whitespace, and out-of-range sampling parameters.
- Run ComfyUI with only required nodes enabled and under a dedicated, minimally privileged service account.
Example validation and safe construction pattern:
bash case "$MODEL_SIZE" in 0.5B|1.7B|3B) ;; *) echo "Error: Unsupported model size"; exit 1 ;; esac [[ "$TEMPERATURE" =~ ^(0(\.[0-9]+)?|1(\.0+)?)$ ]] || { echo "Error: temperature must be between 0 and 1"; exit 1; } [[ "$TOP_P" =~ ^(0(\.[0-9]+)?|1(\.0+)?)$ ]] || { echo "Error: top-p must be between 0 and 1"; exit 1; } [[ "$TOP_K" =~ ^[0-9]+$ ]] || { echo "Error: top-k must be an integer"; exit 1; } WORKFLOW=$(jq -n \ --arg text "$TEXT" \ --arg character "$CHARACTER" \ --arg style "$STYLE" \ --arg model "$MODEL_SIZE" \ --argjson temperature "$TEMPERATURE" \ --argjson top_p "$TOP_P" \ --argjson top_k "$TOP_K" \ '{ "10": { inputs: { character: $character, style: $style, custom_instruct: "" }, class_type: "AILab_Qwen3TTSVoiceInstruct" }, "15": { inputs: { text: $text, model_size: $model, temperature: $temperature, top_p: $top_p, top_k: $top_k }, class_type: "AILab_Qwen3TTSVoiceDesign_Advanced" } }')- Construct the complete workflow and request payload with
