T09 · Insecure Skill Coding Practices
- Location
weather-cn.sh:158- Finding
Remote Weather Response Evaluated as Shell Code
- Content
View full analysis
/dev/null) ``` ```bash local weather weather=$(cat "$tmpfile" | grep -o '[^<]*' | sed 's///' | sed 's/天气预报.*//' | head -1) ``` ```bash echo "WEATHER=${weather:-未知}" echo "TEMP=${temp:-未知}" echo "COLD_INDEX=${cold_index}" echo "SPORT_INDEX=${sport_index}" echo "DRESS_INDEX=${dress_index}" echo "WASH_INDEX=${wash_index}" echo "UV_INDEX=${uv_index}" ``` ```bash local data="$@" # Parse data eval "$data" ``` ### Technical Analysis The script downloads HTML from an external weather service and extracts the contents of its HTML title into the `weather` variable. That value is subsequently serialized as a shell assignment: ```bash WEATHER=<network-controlled value> ``` The generated assignment text is passed to `eval`, which parses and executes its argument as shell code. Quoting `"$data"` when invoking `eval` does not make the contents safe because `eval` performs an additional shell-parsing pass. An attacker who can influence the returned HTML can insert shell metacharacters, command substitutions, or additional commands into the title. For example, a title value containing a command substitution could cause that command to run when the generated `WEATHER` assignment is evaluated. HTTPS limits ordinary network interception, but it does not justify evaluating the response as code. Exploitation remains possible if the upstream service is compromised, its response-generation path is manipulated, DNS or trusted-certificate infrastructure is compromised, or traffic is intercepted through a locally trusted proxy or certificate autho ...[truncated 1471 chars]- Remediation
View remediation
