T09 · Insecure Skill Coding Practices
- Location
src/client.ts:189- Finding
Bearer API Key Can Be Forwarded to an Arbitrary or Insecure Endpoint
- Content
View full analysis
controller.abort(), this.timeout); try { const response = await fetch(url, { ...options, signal: controller.signal, }); ``` The examples allow the destination to come directly from an environment variable: ```typescript const client = new MoltTraderClient({ apiKey: process.env.MOLT_TRADER_API_KEY || '', baseUrl: process.env.MOLT_TRADER_BASE_URL || 'http://localhost:3000', }); ``` ### Technical Analysis The bearer token is legitimately required for the declared authenticated simulator API. Therefore, its transmission is not covert exfiltration by itself. The vulnerability is that `baseUrl` is accepted without validating its protocol or destination before the client attaches the API key to every request. Any caller or environment variable can select an arbitrary HTTP or HTTPS host. An attacker-controlled HTTPS host would receive the bearer token directly. A non-loopback plaintext HTTP endpoint would additionally expose the token to network interception or modification. The default production endpoint uses HTTPS, and the examples default to a loopback development end ...[truncated 1499 chars]- Remediation
View remediation
