Comprehensive security audit of the Ghaymah CLI v2 and web platform. Findings: - [CRITICAL] T1552: Dockerfile & .env Credential Leakage - [CRITICAL] OWASP A07: Missing OTP & Unverified Password Change - [HIGH] T1539: Session Token Revocation Bypass - [MED/HIGH] CWE-400: Configuration Poisoning DoS (Pipeline Hang) Includes: - 8 Proof-of-Concept applications (PoC_Apps/) - Visual evidence & screenshots (Assets/Screenshots/) - Full PDF audit report (Reports/) - Mermaid.js attack flow diagrams in README Auditor: Ziad Mahmoud Ahmed Abdelgwad — Cybersecurity Specialist
24 KiB
╔═══════════════════════════════════════════════════════════════════╗
║ ║
║ ██████╗ ██╗ ██╗ █████╗ ██╗ ██╗███╗ ███╗ █████╗ ██╗ ██╗ ║
║ ██╔════╝ ██║ ██║██╔══██╗╚██╗ ██╔╝████╗ ████║██╔══██╗██║ ██║ ║
║ ██║ ███╗███████║███████║ ╚████╔╝ ██╔████╔██║███████║███████║ ║
║ ██║ ██║██╔══██║██╔══██║ ╚██╔╝ ██║╚██╔╝██║██╔══██║██╔══██║ ║
║ ╚██████╔╝██║ ██║██║ ██║ ██║ ██║ ╚═╝ ██║██║ ██║██║ ██║ ║
║ ╚═════╝ ╚═╝ ╚═╝╚═╝ ╚═╝ ╚═╝ ╚═╝ ╚═╝╚═╝ ╚═╝╚═╝ ╚═╝ ║
║ ║
║ S E C U R I T Y A U D I T R E P O R T ║
║ CLI v2 + Platform ║
║ ║
╚═══════════════════════════════════════════════════════════════════╝
👤 Lead Auditor
|
|
Ziad Mahmoud Ahmed Abdelgwad Cybersecurity Specialist — Penetration Testing & Infrastructure Security |
📋 Executive Summary
Scope: Full-stack security assessment of the Ghaymah CLI v2 command-line tool and its backing web platform, covering Docker container infrastructure, authentication mechanisms, session management, and CI/CD pipeline resilience.
This audit identified 4 distinct vulnerability classes across the CLI tool's deployment pipeline and the platform's authentication layer. Findings range from Critical credential exposure through Dockerfile/.env leakage to High-severity session management flaws and Medium denial-of-service vectors via configuration poisoning.
The assessment leveraged real PoC applications deployed through the Ghaymah CLI to validate each finding under production-equivalent conditions on a Linux amd64 target.
| Metric | Value |
|---|---|
| Total Findings | 4 |
| Critical | 2 |
| High | 1 |
| Medium / High | 1 |
| PoC Apps Created | 8 |
| Audit Duration | 1 Day (Intensive) |
| Methodology | MITRE ATT&CK, OWASP Top 10 |
⚠️ Findings Dashboard
🔬 Vulnerability Deep-Dive
🔴 FINDING 1 — T1552: Dockerfile & .env Credential Leakage
Overview
The Ghaymah CLI packages application source code—including .env files and Dockerfiles containing hardcoded secrets—directly into the container image. These artifacts persist across image layers and are trivially extractable by any entity with access to the image or registry.
Impact
- Credential Theft: API keys, database passwords, and service tokens can be extracted from any pulled image.
- Lateral Movement: Leaked credentials may grant access to adjacent infrastructure components.
- Supply Chain Risk: Downstream consumers of the image inherit the exposed secrets.
Evidence
| Artifact | Description |
|---|---|
Assets/Screenshots/env.png |
Screenshot showing .env file with credentials embedded in image |
Assets/Screenshots/docker.png |
Screenshot showing Dockerfile with exposed build arguments |
PoC_Apps/test-app/ |
PoC application demonstrating the leakage |
Remediation
1. Use Docker BuildKit secrets: --mount=type=secret,id=myenv
2. Add .env to .dockerignore in the CLI scaffolding
3. Inject secrets at runtime via orchestrator (K8s Secrets / Vault)
4. Implement image scanning in CI (Trivy, Grype)
🔴 FINDING 2 — OWASP A07: Missing OTP & Unverified Password Change
Overview
The Ghaymah web platform allows authenticated users to change their password without requiring the current password, an OTP challenge, or any secondary verification. This undermines the entire authentication chain.
Impact
- Account Takeover: An attacker with a stolen session token can silently change the victim's password and lock them out.
- Privilege Escalation: Combined with Finding 3, a single leaked token grants permanent account control.
- Compliance Violation: Fails OWASP ASVS v4.0 §2.2 and NIST SP 800-63B requirements.
Attack Flow
Attacker steals session token (XSS/Network sniff)
└──▶ Calls password change API (no OTP required)
└──▶ Sets new password
└──▶ Original user locked out permanently
Remediation
1. Require current password + OTP for any credential change
2. Implement rate limiting on password change endpoints
3. Send email/SMS notification on password change events
4. Invalidate all existing sessions after password change
🟠 FINDING 3 — T1539: Session Token Revocation Bypass
Overview
Session tokens issued by the Ghaymah platform are not invalidated upon logout or password change. A captured token remains valid and usable indefinitely until its natural expiry.
Impact
- Persistent Unauthorized Access: Attackers can maintain access even after the user changes their password or explicitly logs out.
- Audit Trail Corruption: Legitimate user and attacker actions become indistinguishable.
Evidence
| Artifact | Description |
|---|---|
Assets/Screenshots/Screenshot_2026-08-19_163341.png |
Session validity after logout |
Assets/Screenshots/Screenshot_2026-08-19_163501.png |
Token reuse after password change |
Remediation
1. Implement server-side session store (Redis) with explicit revocation
2. Rotate tokens on privilege-level changes (password change, role update)
3. Set short-lived access tokens (15 min) with refresh token rotation
4. Maintain a token deny-list for immediate revocation
🟡 FINDING 4 — CWE-400: Configuration Poisoning — DoS Pipeline Hang
Overview
The Ghaymah CLI's deployment pipeline does not validate environment variable values before passing them to the backend build worker. Injecting malformed or adversarial values (e.g., multi-line strings, shell metacharacters, excessively long values) causes the worker process to crash or enter an infinite loop, hanging the entire pipeline.
Impact
- Denial of Service: The user's deployment pipeline becomes permanently stuck.
- Resource Exhaustion: Backend workers consume resources without releasing them.
- No Recovery Path: Users cannot cancel or restart the hung pipeline from the CLI.
Architecture / Flow Graph
flowchart TB
subgraph CLIENT ["🖥️ Client Machine"]
A["fa:fa-terminal <b>gy deploy</b><br/>User runs CLI command"]
B["fa:fa-file-code <b>.env / .gy.json</b><br/>Config with malformed vars"]
end
subgraph GHAYMAH_API ["☁️ Ghaymah Backend"]
C["fa:fa-server <b>API Gateway</b><br/>Receives deploy request"]
D["fa:fa-cogs <b>Build Worker</b><br/>Parses env variables"]
E["fa:fa-docker <b>Docker Builder</b><br/>Builds container image"]
end
subgraph FAILURE ["💀 Failure State"]
F["fa:fa-bomb <b>Worker Crash</b><br/>Malformed input causes panic"]
G["fa:fa-hourglass-end <b>Pipeline Hang</b><br/>Indefinite wait state"]
H["fa:fa-ban <b>DoS Achieved</b><br/>No deploy / no cancel"]
end
A -->|"1. Reads config"| B
B -->|"2. Sends payload<br/>(unvalidated)"| C
C -->|"3. Dispatches job"| D
D -->|"4. ✅ Normal flow"| E
D -->|"4. ❌ Malformed input"| F
F -->|"5. No error propagation"| G
G -->|"6. User stuck"| H
style CLIENT fill:#1a1a2e,stroke:#00C853,stroke-width:2px,color:#FFFFFF
style GHAYMAH_API fill:#1a1a2e,stroke:#4A90D9,stroke-width:2px,color:#FFFFFF
style FAILURE fill:#1a1a2e,stroke:#FF4444,stroke-width:2px,color:#FFFFFF
style A fill:#0D1117,stroke:#00C853,color:#FFFFFF
style B fill:#0D1117,stroke:#FFAA00,color:#FFFFFF
style C fill:#0D1117,stroke:#4A90D9,color:#FFFFFF
style D fill:#0D1117,stroke:#4A90D9,color:#FFFFFF
style E fill:#0D1117,stroke:#00C853,color:#FFFFFF
style F fill:#0D1117,stroke:#FF4444,color:#FFFFFF
style G fill:#0D1117,stroke:#FF4444,color:#FFFFFF
style H fill:#0D1117,stroke:#FF0000,color:#FFFFFF
Proof of Concept
The following PoC apps demonstrate this attack:
| PoC App | Purpose |
|---|---|
PoC_Apps/broken-docker-test/ |
Intentionally broken Dockerfile to test error handling |
PoC_Apps/invalid-docker-test/ |
Invalid Docker configuration causing pipeline hang |
PoC_Apps/test-app-3/ |
Malformed env variable injection test |
PoC_Apps/test-app-5/ |
Extended poisoning test with edge-case values |
Evidence
| Artifact | Description |
|---|---|
Assets/Screenshots/logs.png |
Backend logs showing worker crash and hang state |
Remediation
1. Validate all env variable keys/values against a strict schema
2. Implement build timeouts (max 10 min) with automatic cleanup
3. Add a "cancel deployment" feature to the CLI and API
4. Sanitize inputs: reject multi-line values, shell metacharacters, >4KB values
5. Return structured errors to the CLI on worker failure
🔀 Attack Surface Architecture
Complete Mermaid.js diagram mapping the audit scope, attack vectors, and affected components.
flowchart LR
subgraph SCOPE ["🎯 Audit Scope"]
direction TB
CLI["fa:fa-terminal <b>Ghaymah CLI v2</b><br/>gy-linux-amd64"]
WEB["fa:fa-globe <b>Web Platform</b><br/>Dashboard & API"]
end
subgraph VECTORS ["⚔️ Attack Vectors"]
direction TB
V1["T1552<br/>Credential Leakage"]
V2["T1539<br/>Session Bypass"]
V3["CWE-400<br/>Config Poisoning"]
V4["OWASP A07<br/>Auth Failure"]
end
subgraph IMPACT ["💥 Impact"]
direction TB
I1["🔑 Secret Exposure"]
I2["👤 Account Takeover"]
I3["⛔ Pipeline DoS"]
end
CLI --> V1
CLI --> V3
WEB --> V2
WEB --> V4
V1 --> I1
V2 --> I2
V3 --> I3
V4 --> I2
style SCOPE fill:#0D1117,stroke:#4A90D9,stroke-width:2px,color:#FFFFFF
style VECTORS fill:#0D1117,stroke:#FF6600,stroke-width:2px,color:#FFFFFF
style IMPACT fill:#0D1117,stroke:#FF0000,stroke-width:2px,color:#FFFFFF
style CLI fill:#1a1a2e,stroke:#00C853,color:#FFFFFF
style WEB fill:#1a1a2e,stroke:#4A90D9,color:#FFFFFF
style V1 fill:#1a1a2e,stroke:#FF0000,color:#FFFFFF
style V2 fill:#1a1a2e,stroke:#FF6600,color:#FFFFFF
style V3 fill:#1a1a2e,stroke:#FFAA00,color:#FFFFFF
style V4 fill:#1a1a2e,stroke:#FF0000,color:#FFFFFF
style I1 fill:#1a1a2e,stroke:#FF4444,color:#FFFFFF
style I2 fill:#1a1a2e,stroke:#FF4444,color:#FFFFFF
style I3 fill:#1a1a2e,stroke:#FF4444,color:#FFFFFF
📁 Repository Structure
ghaymah-v2-test/
│
├── 📂 Assets/
│ └── 📂 Screenshots/ # Visual evidence & proof captures
│ ├── docker.png # Dockerfile credential exposure
│ ├── env.png # .env file leakage in image layers
│ ├── logs.png # Backend worker crash logs
│ ├── Screenshot_*.png # Session management bypass evidence
│ └── ...
│
├── 📂 PoC_Apps/ # Proof-of-Concept applications
│ ├── 📂 test-app/ # Initial recon & .env leak PoC
│ ├── 📂 test-app-2/ # RCE boundary testing (auto_rce_test.sh)
│ ├── 📂 test-app-3/ # Malformed env variable injection
│ ├── 📂 test-app-5/ # Extended config poisoning tests
│ ├── 📂 test-app-clean/ # Baseline clean deployment
│ ├── 📂 test-app-final/ # Final validated Dockerfile
│ ├── 📂 broken-docker-test/ # Intentionally broken Docker config
│ └── 📂 invalid-docker-test/ # Invalid config → pipeline hang PoC
│
├── 📂 Reports/
│ └── 📄 Ghaymah_CLI_v2_Audit_Report.pdf # Full audit report (PDF)
│
├── 📄 .gitignore # Ignores binary, .env, OS artifacts
├── 📄 organize.sh # Workspace organization script
└── 📄 README.md # ← You are here
🧪 PoC Navigation Guide
📂 How to reproduce the findings
Each folder inside PoC_Apps/ is a standalone application that was deployed through the Ghaymah CLI to validate a specific vulnerability. They are ordered chronologically by testing phase:
Phase 1 — Reconnaissance & Credential Leakage
| Folder | Purpose | Related Finding |
|---|---|---|
test-app/ |
Initial deployment with .env file containing test credentials. Demonstrates that secrets persist in image layers. |
Finding 1 (T1552) |
test-app-2/ |
Includes auto_rce_test.sh — automated script probing for command injection boundaries in the build pipeline. |
Exploratory |
Phase 2 — Configuration Poisoning & DoS
| Folder | Purpose | Related Finding |
|---|---|---|
test-app-3/ |
Dockerfile with malformed ENV directives to test input validation on the backend worker. |
Finding 4 (CWE-400) |
test-app-5/ |
Extended poisoning tests: multi-line values, special characters, oversized payloads. | Finding 4 (CWE-400) |
broken-docker-test/ |
Intentionally invalid Dockerfile to test error handling and pipeline recovery. | Finding 4 (CWE-400) |
invalid-docker-test/ |
Invalid Docker configuration that triggers a permanent pipeline hang. | Finding 4 (CWE-400) |
Phase 3 — Validation & Baseline
| Folder | Purpose | Related Finding |
|---|---|---|
test-app-clean/ |
Clean deployment with no malicious payloads — establishes a working baseline. | Baseline |
test-app-final/ |
Final validated Dockerfile confirming the minimal reproducible deployment. | Baseline |
Note: Findings 2 (OWASP A07) and 3 (T1539) target the web platform and were validated via browser-based testing and API calls, not via PoC apps.
📊 Methodology
🔍 Testing Methodology & Frameworks
| Framework | Application |
|---|---|
| MITRE ATT&CK | Technique mapping for CLI-side findings (T1552, T1539) |
| OWASP Top 10 (2021) | Web platform assessment (A07: Identification & Authentication Failures) |
| OWASP ASVS v4.0 | Authentication & session management verification |
| CWE/CVSS | Vulnerability classification & severity scoring |
| Manual Testing | Custom PoC development, API fuzzing, Docker image inspection |
Tools Used
gy-linux-amd64— Ghaymah CLI v2 binary (target under test)docker— Container runtime for image inspection & layer analysis- Browser DevTools — Session token inspection & API testing
- Custom shell scripts — Automated RCE boundary testing
📎 Full Report
The comprehensive audit report with detailed technical analysis, risk ratings, and remediation roadmap is available as a PDF:
⚖️ Disclaimer
This security audit was conducted in a controlled testing environment with explicit authorization. All findings are reported responsibly to the platform maintainers. The PoC applications and scripts in this repository are provided for educational and verification purposes only. Unauthorized use of these techniques against systems you do not own or have permission to test is illegal and unethical.