The AI Software Engineer That Read Us /etc/shadow
The AI Software Engineer That Read Us /etc/shadow
CRITICAL · UNAUTH ARBITRARY FILE READ (root)The one-liner
We asked an AI coding assistant for /etc/passwd. It said 200 OK. Then it gave us /etc/shadow. Then it offered us .bashrc as a download.
What the screenshot shows
The browser sits on https://www.robocoders.ai, a chat UI branded:
A Code Editor pane, a Jupyter pane, and DevTools Network tab — which tells the whole story:
The Response pane shows /etc/passwd, JSON-wrapped. The Code Editor shows .bashrc with a Download button. The agent's status reads "Agent is initialized, waiting for task..." — it never got a task. It didn't need one.
Why this is worse than a normal LFI
/etc/shadow means the file service had euid 0. Full passwd visible in the pane: root, daemon, bin, sys, sync, games, man, lp, mail, news, uucp, proxy, backup, list, irc, gnats, nobody, the systemd family, messagebus, sshd, chrony, and a uid-1000 user. A stock container image, owned end-to-end by a query string..bashrc with a Download control. UIs that list-and-read usually save-and-write. Arbitrary read as root + probable arbitrary write = drop a key into /root/.ssh/authorized_keys, or overwrite something the app executes. We didn't need to prove the write. The read was enough for the frame.select-file?file= is the obvious one. list-files?path=/ proves directory browsing is half-built already. And sandboxID does double duty — if it's ever concatenated into a path, it's not an arbitrary file read, it's every tenant's files, cross-sandbox. On a multi-tenant AI coding platform, that's the business model gone.Reproduction (from the screenshot, verbatim)
That's it. That's the exploit.
Timeline / status
| When | What |
|---|---|
| Sep 5 (screenshot) | File read observed and captured — passwd + shadow served to an unauthenticated tab. |
| Since then | robocoders.ai has been shuttered. No live disclosure channel, no program to report to. This post is the record. |
| Evidence | One screenshot. That's the point. One frame, full compromise class. |
The funny part
The brand promise was "an AI Software Engineer." What shipped was an exfiltration agent with a chat frontend. No prompt injection, no jailbreak, no clever encoding — the file API simply never asked who we were or why we wanted the shadow file. The agent politely reported it was "waiting for task" while its plumbing served root's password database to a browser tab.
And there's a resonance for anyone tracking platform-security arcs: the same brand once shipped username pages loose enough that admin@ was registerable. Sites die, patterns don't. This screenshot is what the pattern looks like wearing an agentic-coding costume.
Takeaways (for builders)
file= parameter is a path. Treat it like one: allowlist, jail to a sandbox root, resolve symlinks after containment, and run the file service as nobody so /etc/shadow is unreadable even on a bad day.list-files?path=/ is a finding all by itself. If your editor can browse /, it can read /.Cross-reference: "LongLost" series — methodology over dramatization, screenshots over claims.



0 Comments:
Post a Comment
Subscribe to Post Comments [Atom]
<< Home