Skip to content

[Aikido] Fix shell injection detection in double-quoted regions with escaped characters - #508

Closed
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137915711-hpay
Closed

aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137915711-hpay

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Oct 8, 2026

Copy link
Copy Markdown
Contributor

This patch addresses shell injection detection vulnerabilities in the command encapsulation analysis. The fix improves detection of command substitutions within double-quoted strings and properly handles escaped quote characters that should not be treated as quote delimiters. Changes were made to lib/request-processor/vulnerabilities/shell-injection/isSafelyEncapsulated.go to enhance the parseQuoteRegions function's ability to accurately identify unsafe command patterns. These improvements reduce false negatives in shell injection vulnerability detection.

✅ 1 issue fixed by this PR
Issue Severity           Description
CodeAudit#811697768
HIGH
isSafelyEncapsulated identifies quote regions without tracking shell escape state and treats any tainted occurrence inside a double-quoted region as safe when the tainted text lacks $, backticks, backslashes, and !. Consequently, a command such as echo "$(id)" with request-derived input id is classified as safely encapsulated even though the shell executes id as a command substitution. The same parser also treats escaped quotes as quote delimiters, allowing input such as foo;id # in echo \"foo;id #\" to be classified as quoted even though the quotes are literal, the semicolon is active, and the comment suppresses the trailing quote. In either case, detectShellInjection returns before containsShellSyntax, so the PHP shell hook does not report or block the operation.

@hansott hansott closed this Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant