# Code injection via device inventory?

**URL:** <https://hub.mender.io/t/code-injection-via-device-inventory/6858>\
**Category:** General Discussions\
**Tags:** mender-client, security, inventory\
**Created:** [May 29, 2024, 1:11pm UTC](https://hub.mender.io/t/code-injection-via-device-inventory/6858 "2024-05-29T13:11:31Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mister\_kanister](https://avatars.discourse-cdn.com/v4/letter/m/8edcca/32.png) [@mister\_kanister](https://hub.mender.io/u/mister_kanister)\
**Post date:** [May 29, 2024, 1:11pm UTC](https://hub.mender.io/t/code-injection-via-device-inventory/6858/1 "2024-05-29T13:11:31Z")

</div>

Good Day, Friends!

I’m working on an mender artifact that will extend the device inventory. It is a more general question about security because I do not understand the implications.

Via `--type script` update module I have create an inventory file on the fly.

```auto
# realpath mender-inventory-basic-info 
/usr/share/mender/inventory/mender-inventory-basic-info
# cat /usr/share/mender/inventory/mender-inventory-basic-info
#!/bin/sh
echo 'uptime'=$(uptime -p)
echo 'uptime_date'=$(uptime -s)

```

Our devices are not temper proof and can be modified by the “customer” as they please.

1. To which risks is the mender backend exposed in such a case?
2. Is it possible to perform code injection with device inventory info?  
Assume the customer modified the device inventory in such a way that it will produce malicious mongodb queries that will attack the backend. How realistic is this?

It is a more theoretical discussion.

---

<div class="post-metadata">

**Author:** ![TheYoctoJester](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/theyoctojester/32/1444_2.png) [@TheYoctoJester](https://hub.mender.io/u/TheYoctoJester)\
**Post date:** [June 3, 2024, 3:22pm UTC](https://hub.mender.io/t/code-injection-via-device-inventory/6858/2 "2024-06-03T15:22:21Z")

</div>

Hi @mister_kanister,

Interesting question! Thinking a bit about it, the question expands to: “what if an attacker controls an authenticated device?”. As far as I know, at some point API throttling will occur, but maybe @kjaskiewiczz can share some more information.

Greets,  
Josef
