The codebase exhibits critical supply chain and privilege escalation vulnerabilities. Specifically, it executes unpinned, unauthenticated remote bash scripts directly into root contexts via curl | bash during setup and automated background updates orchestrated through passwordless sudoers rules.
| Severity |
Audit Vector |
File & Line |
Code Snippet / Mechanism |
Exploitation / Risk Analysis |
| CRITICAL |
Remote Code Execution / Supply Chain |
battery.sh:655, battery.sh:144, update.sh:56 |
curl -sS "$github_url_update_sh" | bash inside update_silent called via sudo -n |
Unauthenticated RCE as root. The sudoers rule (ALL ALL = NOPASSWD: /usr/local/co.palokaj.battery/battery update_silent) allows any local unprivileged process to trigger an automated fetch and root execution of mutable remote code from GitHub branch main without checksum or GPG signature verification. |
| HIGH |
Insecure Privilege Escalation |
app/modules/battery.js:218, setup.sh:41 |
osascript -e "do shell script \"curl -s https://raw.githubusercontent.com/.../setup.sh | bash -s -- $USER\" with administrator privileges" |
Elevation of privilege via network stream. Prompts user for admin credentials via AppleScript dialog and executes unhashed remote script directly into root shell. Vulnerable to MITM (where TLS termination is compromised), upstream GitHub account takeover, or branch poisoning. |
The codebase exhibits critical supply chain and privilege escalation vulnerabilities. Specifically, it executes unpinned, unauthenticated remote bash scripts directly into root contexts via curl | bash during setup and automated background updates orchestrated through passwordless sudoers rules.
curl -sS "$github_url_update_sh" | bashinsideupdate_silentcalled viasudo -nroot. Thesudoersrule (ALL ALL = NOPASSWD: /usr/local/co.palokaj.battery/battery update_silent) allows any local unprivileged process to trigger an automated fetch and root execution of mutable remote code from GitHub branchmainwithout checksum or GPG signature verification.osascript -e "do shell script \"curl -s https://raw.githubusercontent.com/.../setup.sh | bash -s -- $USER\" with administrator privileges"