Skip to content

[BUG] dangerous secret name warning list is missing BASH_ENV, ENV, ZDOTDIR, IFS and other interpreter vectors #561

Description

@pochtrack

Describe the bug

The CLI's dangerous-secret-name warning list (dangerousSecretNames in pkg/controllers/secrets.go) is missing several well-known environment-variable code-execution vectors — most notably BASH_ENV, plus ENV, ZDOTDIR, IFS, PYTHONSTARTUP, RUBYOPT, and JAVA_TOOL_OPTIONS.

doppler run warns when the config contains dangerous secret names (per https://docs.doppler.com/docs/accessing-secrets#injection), and the docs explicitly note the list "is not exhaustive". Still, BASH_ENV is arguably the most common shell-hijack vector on Linux/macOS: non-interactive bash sources $BASH_ENV before executing a command, so a secret named BASH_ENV pointing at any shell script at a predictable path (repo scripts, CI artifact dirs, /tmp files created by the pipeline) executes in every doppler run consumer's environment. Currently it is injected with no warning, while e.g. LD_PRELOAD gets one.

Confirmed on a dev build against a mock API: with secrets BASH_ENV=/path/script, ZDOTDIR=/dir, IFS=;;, LD_PRELOAD=/lib.so:

  • the warning output listed only LD_PRELOAD
  • BASH_ENV, ZDOTDIR, and IFS were all injected into the child environment
  • the script referenced by BASH_ENV was sourced and executed by the spawned /bin/bash -c child

(Note: IFS requires no file at all — it alters word-splitting of the user's own --command.)

To Reproduce

  1. Configure secrets including BASH_ENV pointing to an existing shell script and LD_PRELOAD pointing to a nonexistent path
  2. doppler run --command '/bin/bash -c "true"' --debug
  3. Observe the warning lists only LD_PRELOAD; the BASH_ENV script executes with no warning

Expected behavior

The warning list should include the standard shell/interpreter-hijack variable names — at minimum BASH_ENV, ENV, ZDOTDIR, IFS, PYTHONSTARTUP, RUBYOPT, JAVA_TOOL_OPTIONS — so users relying on the CLI's warning get consistent coverage of the vectors the docs describe.

Suggested fix (one-line addition to dangerousSecretNames in pkg/controllers/secrets.go):

var dangerousSecretNames = [...]string{
	// Operating Systems environment variable names
	// Linux
	"PROMPT_COMMAND",
	"LD_PRELOAD",
	"LD_LIBRARY_PATH",
	"BASH_ENV", // non-interactive bash sources this
	"ENV",      // POSIX sh sources this
	"ZDOTDIR",  // zsh sources $ZDOTDIR/.zshrc
	"IFS",      // alters shell word-splitting
	...

Desktop (please complete the following information):

  • OS: Linux
  • Version 7.0.0-28-generic

CLI Version:
Built from source @ b618e5f (version dev); present in current main.

Additional context

Found during a security review of the CLI. The docs already document the RCE danger and recommend mounting as the remediation, so this is a warning-completeness improvement rather than a security report. The same review also confirmed PATH/PS1/HOME reserved-key handling works as intended. Happy to open a PR.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions