Skip to content

[Aikido] Fix shell injection bypass in nested quote context parsing - #749

Closed
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137922154-htmn
Closed

aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137922154-htmn

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Oct 8, 2026

Copy link
Copy Markdown

This patch addresses a shell injection vulnerability where nested quote contexts could bypass detection by examining only adjacent characters around user input. The fix implements proper shell quoting state parsing that tracks quote context from the beginning of the command rather than relying on local character analysis. Changes were made to is_safely_encapsulated.py to enhance quote context tracking logic, with corresponding test cases added to detect_shell_injection_test.py and is_safely_encapsulated_test.py to validate the fix against nested quote scenarios.

✅ 1 issue fixed by this PR
Issue Severity           Description
CodeAudit#811707943
HIGH
The helper decides safety from the characters adjacent to the user-controlled substring rather than from shell parsing state. For user_input = "$(id)" and command = 'echo "\'$(id)\'"', it observes matching apostrophes and returns True. Those apostrophes occur inside an active outer double-quoted region and do not disable command substitution. detect_shell_injection() therefore returns before calling contains_shell_syntax(), which would flag $. The false negative affects the shared detection path used before os.system and subprocess.Popen(..., shell=True), allowing a request-controlled value already interpolated into such a command to execute with the consuming process's privileges.

@hansott hansott closed this Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant