T09 · Insecure Skill Coding Practices
- Location
scripts/daily_tech_digest.py:34- Finding
Server-Side Request Forgery Through Unrestricted News URLs
- Content
View full analysis
Vulnerability Details
File Location:
scripts/daily_tech_digest.py, lines 34-52, 157-160, and 220
Vulnerability Type: Unrestricted outbound URL fetching and SSRF
Risk Level: HighVulnerable Code
python def fetch_url(url: str) -> str | None: """Fetch URL and return HTML text.""" try: req = Request(url, headers={"User-Agent": UA}) with urlopen(req, timeout=TIMEOUT) as resp: raw = resp.read() for enc in ("utf-8", "gbk", "gb2312"): try: return raw.decode(enc, errors="replace") except (LookupError, UnicodeDecodeError): continue return raw.decode("utf-8", errors="replace") except (URLError, HTTPError, OSError) as e: log(f"Fetch failed {url}: {e}") return NoneThe external URL is subsequently passed directly into the fetching routine:
python content = extract_article_content(item['url'], max_length=400)Technical Analysis
News items are obtained from the external local dependency
daily-tech-broadcast. Each item can provide an arbitraryurl, which is passed tourllib.request.urlopenwithout validation.The implementation does not:
- Restrict requests to HTTPS.
- Apply an allowlist of trusted news domains.
- Reject URLs containing embedded credentials.
- Reject non-HTTP URL schemes such as
file:. - Resolve and reject loopback, private, link-local, multicast, or reserved IP addresses.
- Revalidate the destination after HTTP redirects.
- Limit the maximum response size before reading it into memory.
Consequently, an attacker who controls or compromises the news feed can cause the skill to request resources that are not legitimate public news articles.
Attack Path
- An attacker compromises the
daily-tech-broadcastdata source or otherwise causes it to return a crafted news item. - The ...[truncated 1710 chars]
- Remediation
View remediation
Remediation Suggestions
- Permit only
httpsURLs and reject all other schemes. - Maintain an explicit allowlist of approved news hostnames.
- Reject URLs with usernames, passwords, malformed ports, or ambiguous host representations.
- Resolve the hostname before connecting and reject all loopback, private, link-local, multicast, unspecified, and reserved IPv4 and IPv6 addresses.
- Disable automatic redirects or validate the scheme, hostname, and resolved address after every redirect.
- Protect against DNS rebinding by connecting only to the validated resolved address while preserving the intended TLS hostname.
- Apply response-size and content-type limits before reading the body.
- Run the fetcher with restricted network access so it cannot reach localhost, cloud metadata addresses, or private network ranges.
- Treat all retrieved article text as untrusted when embedding it in Markdown or forwarding it to downstream systems.
- Permit only
