Repository navigation
[Aikido] Fix shell injection detection in double-quoted regions with escaped characters - #508
Closed
aikido-autofix[bot] wants to merge 1 commit into
Closed
aikido-autofix[bot] wants to merge 1 commit into
aikido-autofix[bot] wants to merge 1 commit into
Conversation
…mand substitutions in...
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This patch addresses shell injection detection vulnerabilities in the command encapsulation analysis. The fix improves detection of command substitutions within double-quoted strings and properly handles escaped quote characters that should not be treated as quote delimiters. Changes were made to
lib/request-processor/vulnerabilities/shell-injection/isSafelyEncapsulated.goto enhance theparseQuoteRegionsfunction's ability to accurately identify unsafe command patterns. These improvements reduce false negatives in shell injection vulnerability detection.✅ 1 issue fixed by this PR
isSafelyEncapsulatedidentifies quote regions without tracking shell escape state and treats any tainted occurrence inside a double-quoted region as safe when the tainted text lacks$, backticks, backslashes, and!. Consequently, a command such asecho "$(id)"with request-derived inputidis classified as safely encapsulated even though the shell executesidas a command substitution. The same parser also treats escaped quotes as quote delimiters, allowing input such asfoo;id #inecho \"foo;id #\"to be classified as quoted even though the quotes are literal, the semicolon is active, and the comment suppresses the trailing quote. In either case,detectShellInjectionreturns beforecontainsShellSyntax, so the PHP shell hook does not report or block the operation.