T09 · Insecure Skill Coding Practices
- Location
scripts/oauth_setup.py:27- Finding
Unsafe Deserialization of OAuth Credentials Using Pickle
- Content
View full analysis
Vulnerability Details
File Location:
scripts/oauth_setup.py, lines 27-29
Vulnerability Type: Unsafe deserialization
Risk Level: HighVulnerable Code:
python if TOKEN_FILE.exists(): with open(TOKEN_FILE, 'rb') as token: creds = pickle.load(token)Technical Analysis
The application deserializes
~/.google-calendar-token.picklewith Python'spickle.load()without validating the file's integrity, ownership, permissions, type, or contents. Pickle is an executable serialization format: specially constructed objects can invoke arbitrary callables during deserialization through mechanisms such as__reduce__.Merely opening the file and calling
pickle.load()is therefore sufficient to execute a malicious payload. The code trusts the token based only on its existence. No signature or other authenticity check establishes that the file was generated by this application.Exploitation requires the attacker to create, replace, or modify the token file. Possible enabling conditions include another compromised process running as the user, insecure home-directory permissions, an unsafe backup restoration, or another application writing attacker-controlled content to that path.
Attack Path
- The attacker obtains the ability to write to or replace
~/.google-calendar-token.pickle. - The attacker creates a malicious pickle whose deserialization routine launches a command or invokes attacker-selected Python code.
- The victim invokes any operation that calls
authenticate(), including listing or modifying calendar events. authenticate()finds the token file and passes it directly topickle.load().- The embedded deserialization payload executes before credential validity is checked.
- The payload runs with the operating-system privileges and environment of the user who launched the Skill.
Impact Assessment
Successful exploitation provides arbitrary code execut ...[truncated 607 chars]
- The attacker obtains the ability to write to or replace
- Remediation
View remediation
Remediation Suggestions
- Replace pickle storage with a non-executable format such as JSON.
- Serialize only the required credential fields and reconstruct credentials with the official Google authentication APIs, for example through
Credentials.from_authorized_user_info. - Validate the expected JSON schema and reject unknown or incorrectly typed fields.
- Create the token file atomically with owner-only permissions such as
0600. - Before reading, reject symbolic links and verify that the file is a regular file owned by the current user.
- If tampering by processes with file access is within the threat model, protect the serialized credentials with an operating-system credential store or authenticated encryption.
- Revoke and reissue existing OAuth tokens if token-file integrity may already have been compromised.
