T09 · Insecure Skill Coding Practices
- Location
scripts/searxng.py:57- Finding
TLS Certificate Verification Is Unconditionally Disabled
- Content
View full analysis
Vulnerability Details
File Location:
scripts/searxng.py, lines 57-62; related warning suppression at line 20
Vulnerability Type: Improper certificate validation
Risk Level: MediumVulnerable Code
python # Suppress SSL warnings for local self-signed certificates warnings.filterwarnings('ignore', message='Unverified HTTPS request')python # Disable SSL verification for local self-signed certs response = httpx.get( f"{SEARXNG_URL}/search", params=params, timeout=30, verify=False # For local self-signed certs )Technical Analysis
Every HTTPS request is made with
verify=False, regardless of whether the configured SearXNG endpoint is local, public, or uses a publicly trusted certificate. This disables certificate-chain and hostname validation, removing HTTPS server authentication.Although the stated purpose is compatibility with local self-signed certificates, the behavior also applies to remote instances explicitly supported by
README.md. An attacker with a network position can therefore impersonate the configured SearXNG server using any certificate. Warning suppression further reduces the visibility of this insecure connection behavior.The search query is sent as the
qrequest parameter, and the returned JSON is trusted and rendered or emitted to downstream programs. Consequently, a successful interception can disclose searches and replace search results without detection.Attack Path
- A user configures
SEARXNG_URLwith an HTTPS SearXNG instance, particularly a remote or public instance. - The attacker obtains a network interception position, such as through a malicious Wi-Fi access point, compromised proxy, DNS manipulation, or local network compromise.
- The attacker presents an arbitrary TLS certificate while impersonating the configured endpoint.
- Because
verify=Falseis set, the client accepts the attacker's certificate. - The attacker reads the search query and returns at ...[truncated 754 chars]
- A user configures
- Remediation
View remediation
Remediation Suggestions
- Enable certificate verification by default:
python response = httpx.get( f"{SEARXNG_URL.rstrip('/')}/search", params=params, timeout=30, verify=True, )- If self-signed certificates must be supported, allow users to provide a specific CA certificate rather than disabling verification:
python SEARXNG_CA_BUNDLE = os.getenv("SEARXNG_CA_BUNDLE") verify = SEARXNG_CA_BUNDLE if SEARXNG_CA_BUNDLE else True- If an explicit insecure mode is retained for development, require a clearly named opt-in such as
SEARXNG_INSECURE_TLS=true, display a prominent warning, and document that it must not be used with remote instances. - Remove the global warning filter so insecure transport is not silently hidden.
- Prefer
http://localhostonly for loopback-only deployments and authenticated, certificate-validated HTTPS for remote instances. - Add tests confirming that invalid certificates and hostname mismatches are rejected by default.
