T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/render_daily_poster.py:189- Finding
Unrestricted Local File Access and Server-Side Request Forgery Through Poster Specifications
- Content
View full analysis
Path | None: if not path_value: return None raw = Path(os.path.expandvars(path_value)).expanduser() candidate = raw if raw.is_absolute() else base_dir / raw return candidate.resolve() if candidate.exists() else None @lru_cache(maxsize=32) def fetch_binary_payload(url: str, *, timeout: float = 8.0) -> tuple[str, bytes] | None: request = Request(url, headers={"User-Agent": "daily-poster/1.0"}) try: with urlopen(request, timeout=timeout) as response: payload = response.read() mime = response.headers.get_content_type() if not mime or mime == "application/octet-stream": guessed, _ = mimetypes.guess_type(urlparse(url).path) mime = guessed or "image/png" return mime, payload except (HTTPError, URLError, TimeoutError, OSError, ValueError): return None def load_image_asset(path_value: str | None, *, base_dir: Path) -> tuple[str, bytes] | None: source = str(path_value or "").strip() if not source: return None if source.startswith(("http://", "https://")): return fetch_binary_payload(source) path = resolve_image(source, base_dir) if path is None: return None mime, _ = mimetypes.guess_type(str(path)) return (mime or "image/png", path.read_bytes()) ``` The loaded bytes are subsequently embedded directly into the SVG: ```python mime, payload = asset data = base64.b64encode(payload).decode("ascii") fit = "xMidYMid slice" if mode == "cover" else "xMidYMid meet" self.add(f'- Remediation
View remediation
