T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/fire_detection_analysis.py:53- Finding
Shared Fallback Identity Breaks Cross-User Report Isolation
- Content
View full analysis
Vulnerability Details
File Location:
scripts/fire_detection_analysis.py:53,skills/smyx_common/scripts/util.py:449-460
Vulnerability Type: Authentication context confusion and cross-user data access
Risk Level: HighRelevant code:
python # scripts/fire_detection_analysis.py:53 OpenIdUtil.resolve_current_open_id( args.open_id, use_current=bool(args.open_id) )python # skills/smyx_common/scripts/util.py:449-460 @classmethod def resolve_current_open_id(cls, open_id=None, use_current=True): """Resolve and initialize the current open-id.""" resolved_open_id = (open_id or "").strip() if isinstance(open_id, str) else open_id if not resolved_open_id and use_current: resolved_open_id = ConstantEnum.CURRENT__OPEN_ID or ConstantEnum.CURRENT__USER_NAME if not resolved_open_id: resolved_open_id = cls.get_api_key_file_open_id() if not resolved_open_id: resolved_open_id = cls.get_or_create_default_open_id() ConstantEnum.CURRENT__OPEN_ID = resolved_open_id if not ConstantEnum.CURRENT__USER_NAME: ConstantEnum.CURRENT__USER_NAME = resolved_open_id return resolved_open_idTechnical Analysis
The entry point sets
use_currentaccording to whether the hidden--open-idargument was explicitly supplied. During an ordinary invocation,args.open_idis absent anduse_currentbecomesFalse.Consequently,
resolve_current_open_id()skips the current upstream identity stored inConstantEnum.CURRENT__OPEN_IDorConstantEnum.CURRENT__USER_NAME. Those values can be initialized from upstream sender environment variables, but they are ignored on the normal execution path.The code instead selects an identity from the workspace-wide
data/smyx-api-key.txtfile or creates/reuses a default user from the shared SQLite database. API authentication and report filtering subsequently operate under this share ...[truncated 1929 chars]- Remediation
View remediation
Remediation Suggestions
- Always prefer the validated upstream sender identity when one is available:
python OpenIdUtil.resolve_current_open_id(args.open_id, use_current=True) - Remove the coupling between
use_currentand the presence of the hidden command-line argument. - Use a generated fallback identity only when no authenticated upstream identity exists.
- Namespace fallback identities and local credential records by authenticated tenant and user rather than sharing one workspace-wide default.
- Enforce report ownership and tenant isolation on the server for list, result, and export endpoints; do not rely solely on a client-supplied username.
- Add integration tests with two distinct upstream users to verify that each user can list and retrieve only their own analysis records.
- Reject ambiguous identity states instead of silently falling back in multi-user deployments.
- Always prefer the validated upstream sender identity when one is available:
