T09 · Insecure Skill Coding Practices
- Location
scripts/get_data.py:466- Finding
API Key Disclosure Through an Unrestricted API Endpoint
- Content
View full analysis
Vulnerability Details
File Location:
scripts/get_data.py, lines 466-489
Vulnerability Type: Credential disclosure through attacker-controlled network destination
Risk Level: HighVulnerable Code
python async def query_mx_finance_data( query: str, output_dir: Optional[Path] = None, api_base: Optional[str] = None, ) -> Dict[str, Any]: """ 执行金融数据主查询流程并输出文件结果。 完成接口请求、业务状态校验、表格解析与文件写入。 返回包含文件路径、行数及错误信息的结果字典。 """ output_dir = output_dir or _get_default_output_dir() output_dir = Path(output_dir) output_dir.mkdir(parents=True, exist_ok=True) url = api_base or DEFAULT_SEARCH_API_URL result = _make_result_base(query) try: body = _build_request_body(query) api_key = EM_API_KEY async with httpx.AsyncClient(timeout=30.0) as client: resp = await client.post( url, json=body, headers={ "Content-Type": "application/json", "em_api_key": api_key, }, )Technical Analysis
The public
query_mx_finance_datafunction accepts an unrestrictedapi_baseparameter and uses it directly as the destination of an authenticated HTTP request. TheEM_API_KEYcredential is attached to the request regardless of the destination's scheme, hostname, port, or ownership.Although the command-line interface does not expose
api_base, other Python code can import and invoke this function. An integration that derivesapi_basefrom configuration or user-controlled input can therefore disclose the API key to an arbitrary server. The code does not require HTTPS or allowlist the documented East Money host.Attack Path
- An attacker gains control over an application's
api_baseinput or related configuration. - The attacker supplies a URL under their control, such ...[truncated 873 chars]
- An attacker gains control over an application's
- Remediation
View remediation
Remediation Suggestions
- Remove the
api_baseparameter from production-facing interfaces if endpoint substitution is unnecessary. - If endpoint configurability is required for testing, separate the test client from the production authenticated client.
- Require an
httpsscheme and allowlist the exact expected hostname, such asai-saas.eastmoney.com. - Reject URLs containing unexpected ports, embedded credentials, fragments, or noncanonical hostnames.
- Ensure credentials are never forwarded to a different origin during redirects. Keep redirects disabled or validate every redirect target before resending authenticated requests.
- Add tests confirming that HTTP URLs, attacker-controlled hosts, subdomain lookalikes, and malformed URLs are rejected before any request is sent.
- Rotate
EM_API_KEYif the affected function has previously been invoked with an untrusted endpoint.
- Remove the
