Skip to content

[Aikido] Fix shell injection bypass in is_safely_encapsulated quote validation - #442

Closed
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137952816-tfh3
Closed

aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/code-audit-137952816-tfh3

Conversation

@aikido-autofix

@aikido-autofix aikido-autofix Bot commented Oct 8, 2026

Copy link
Copy Markdown

This patch addresses shell injection bypass vulnerabilities in the shell injection scanner's quote validation logic. The is_safely_encapsulated method previously used a naive character adjacency check that could be bypassed using empty quote pairs or escaped quote characters. The fix replaces this with a proper shell quote state parser that correctly tracks escape sequences and validates that user input is genuinely enclosed within active quote delimiters. Changes were made to lib/aikido/zen/scanners/shell_injection/helpers.rb with corresponding test coverage added to test/aikido/zen/scanners/shell_injection_scanner_test.rb and test/aikido/zen/scanners/shell_injection/helpers_test.rb.

✅ 1 issue fixed by this PR
Issue Severity           Description
CodeAudit#811806191
HIGH
The helper splits the command on the user input and treats matching neighboring quote characters as proof that the input is safely encapsulated. For printf '';id #'' with input ;id #, the neighboring characters are both single quotes, but those quotes do not delimit the payload: the semicolon remains an active command separator. Similarly, escaped quote boundaries such as echo \";id;echo\" with input ;id;echo can satisfy the adjacency check even though the quotes are literal shell characters. ShellInjectionScanner#attack? returns before contains_shell_syntax, so the pre-sink hook does not raise and the original single-string Kernel#system, Kernel#spawn, or backtick operation remains reachable.

@codecov

codecov Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 97.18310% with 2 lines in your changes missing coverage. Please review.

Files with missing lines Patch % Lines
lib/aikido/zen/scanners/shell_injection/helpers.rb 97.18% 2 Missing ⚠️

📢 Thoughts on this report? Let us know!

@hansott hansott closed this Oct 8, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant