T09 · Insecure Skill Coding Practices
- Location
scripts/oauth_setup.py:31- Finding
Arbitrary Code Execution Through Unsafe Pickle Deserialization
- Content
View full analysis
Vulnerability Details
File Location:
scripts/oauth_setup.py, lines 31-33
Vulnerability Type: Unsafe deserialization of a locally stored authentication token
Risk Level: HighVulnerable Code
python if TOKEN_FILE.exists(): with open(TOKEN_FILE, 'rb') as token: creds = pickle.load(token)The affected token path is defined at line 19:
python TOKEN_FILE = Path.home() / '.google-sheets-token.pickle'Technical Analysis
Python pickle data is executable serialization rather than a safe data-only format. During
pickle.load(), specially constructed objects can invoke arbitrary callables through reconstruction methods such as__reduce__.The application loads
~/.google-sheets-token.picklewithout validating its integrity, ownership, permissions, or provenance. Consequently, the mere existence of a maliciously replaced token file is sufficient to trigger code execution whenauthenticate()is called. Authentication-dependent operations in both scripts can reach this code path.Exploitation requires an attacker or compromised local process to obtain write access to the token file or its parent home directory. The vulnerability does not independently provide that initial access, but it converts token-file modification into arbitrary code execution.
Attack Path
- An attacker gains the ability to create or replace
~/.google-sheets-token.pickle, such as through another compromised process running as the same user, an insecure backup restoration process, or incorrectly configured file permissions. - The attacker creates a malicious pickle whose reconstruction routine executes an operating-system command.
- The victim invokes OAuth setup or any spreadsheet operation that calls
authenticate(). - The code detects the token file and passes it directly to
pickle.load(). - The malicious reconstruction routine executes before credential validity is checked.
...[truncated 683 chars]
- An attacker gains the ability to create or replace
- Remediation
View remediation
Remediation Suggestions
Replace pickle serialization with a non-executable credential format supported by the Google authentication library. For example, save credentials using
Credentials.to_json()and restore them usingCredentials.from_authorized_user_file().Additional hardening should include:
- Create the token file with permissions restricted to its owner, such as mode
0600. - Verify that the file is a regular file, is owned by the expected user, and is not a symbolic link before reading it.
- Write updated credentials atomically through a securely created temporary file in the same directory.
- Reject token files with unexpectedly permissive ownership or access modes.
- If migration from pickle is necessary, do not automatically deserialize the existing file. Require the user to delete it and complete OAuth authentication again.
- Protect the home directory and token path from writes by untrusted users or processes.
- Create the token file with permissions restricted to its owner, such as mode
