Executive brief
The thi.ng/egf library is a data format parser used in Node.js applications. When the GPG decryption feature is enabled, it fails to properly validate encrypted property values, allowing an attacker to inject arbitrary operating system commands through specially crafted backtick characters. This could lead to unauthorized code execution on servers processing untrusted EGF files.
Technical details
The vulnerability is an OS command injection (CWE-78) in the `#gpg`-tagged property value handling when decryption is enabled. The root cause is improper neutralization of backtick (`) characters in encrypted values, which are interpreted as shell command substitution by the underlying GPG decryption logic. An attacker must supply a malicious EGF file with a `#gpg`-tagged value containing backticks and the application must have the `decrypt: true` option enabled. No authentication is required; network reachability depends on how the application accepts EGF input. Successful exploitation allows arbitrary command execution with the privileges of the Node.js process. The fix was released in version 0.4.0 (2021-03-27).
Affected products
- thi.ng egf <0.4.0
Timeline
- 2021-03-30: disclosed
- 2021-03-27: patched: v0.4.0