T09 · Insecure Skill Coding Practices
- Location
scripts/publish.sh:178- Finding
Shell Command Injection Through Dynamically Constructed eval Command
- Content
View full analysis
/tmp/wechat-publisher-pwned; #' ``` 3. The script appends this value to `publish_cmd`. 4. `eval` reparses the resulting command string as shell program text. 5. The injected command executes with the same operating-system privileges as the user running the publishing script. The same issue can arise w ...[truncated 882 chars]- Remediation
View remediation
