github / github/codeql

False negative: missing os.exec* APIs with `sh -c` as sink in py/code-injection.

未关闭
#21,735 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
question
主要语言
CodeQL
星标
10.1k
派生
2.1k
平均合并
2 天 15 小时
30 天内合并 PR
141

描述

**Description of the issue**

py/code-injection flags command injection when the code uses os.system(...) or subprocess.run(..., shell=True), but it does not flag the same tainted command when it is executed through Python os.exec* APIs with sh -c.

A minimal example:
```python
files = request.args.get("files", "")
os.execl("/bin/sh", "sh", "-c", "ls " + files)
```

I also tested equivalent variants (os.execlp, os.execve, and subprocess.run(["sh","-c", ...])) and they were not reported either, while the os.system and shell=True controls were reported.

Sink pattern example in the wild:
https://github.com/ziyan/ssh-otp/blob/ad23edded03ee7d198417d99457d3cfa3df814d1/ssh-otp#L90
There are also code using `python -c
https://github.com/davidfraser/dbghelper/blob/f12b91b468bb640f1cb9d19733afef7696eee9fa/dbg.py#L47

贡献指南

打开贡献指南

调研方向

从 py/code-injection 查询开始,将其现有的 os.system 和 subprocess.run(shell=True) sink 处理与报告的 os.execl 示例进行比较。运行最小示例和等效变体,然后验证通过 sh -c 传递的受污染命令会被报告,同时现有控制仍然得到覆盖。

由索引模型根据 Issue 内容生成。

评估

技术栈
python
领域
security
Issue 类型
缺陷
难度
3/5
预计耗时
1-2 天
活跃度
冷清
描述清晰度
基本清楚
新手友好度
55/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。