T09 · Insecure Skill Coding Practices
- Location
scripts/train_style.py:32- Finding
Unrestricted Training URL Validation Enables Server-Side Request Forgery
- Content
View full analysis
Vulnerability Details
File Location:
scripts/train_style.py:22-48andscripts/train_style.py:83-94
Vulnerability Type: Server-Side Request Forgery (SSRF)
Risk Level: MediumVulnerable Code
python def load_urls(args): """Collect training image URLs from --urls and/or --urls-file.""" urls = list(args.urls or []) if args.urls_file: with open(args.urls_file) as f: for line in f: line = line.strip() if line and not line.startswith("#"): urls.append(line) return urls def validate_urls(urls): """HEAD-check every URL to catch 404s before wasting CU on training.""" print(f"Validating {len(urls)} image URLs...", file=sys.stderr) bad = [] for i, url in enumerate(urls): try: r = requests.head(url, timeout=10, allow_redirects=True) if r.status_code >= 400: bad.append((url, r.status_code)) print(f" [{i+1}/{len(urls)}] FAIL {r.status_code}: {url[:80]}", file=sys.stderr) else: print(f" [{i+1}/{len(urls)}] OK: {url[:80]}", file=sys.stderr) except requests.RequestException as e: bad.append((url, str(e))) print(f" [{i+1}/{len(urls)}] FAIL: {url[:80]} ({e})", file=sys.stderr) return badpython # Resolve local files to hosted URLs resolved_urls = [] for url in urls: resolved_urls.append(ensure_image_url(url, api_key)) # Validate URLs are reachable if not args.skip_validation: bad = validate_urls(resolved_urls) if bad: print(f"\nError: {len(bad)} URLs failed validation. Fix them or use --skip-validation.", file=sys.stderr) for url, reason in bad: print(f" {reason}: {url[:100]}", file=sys.stderr) sys.exit(1)Technical Analysis
Training URLs supplied through `--url ...[truncated 2171 chars]
- Remediation
View remediation
Remediation Suggestions
- Permit only
httpsURLs and reject URLs containing embedded credentials. - Resolve the hostname before connecting and reject every address that is loopback, private, link-local, multicast, unspecified, or reserved.
- Disable automatic redirects or validate the hostname and resolved IP address at every redirect hop.
- Apply an allowlist of trusted image-hosting domains when operationally feasible.
- Validate that the returned content type is an expected image media type.
- Use a controlled outbound proxy or network policy that blocks access to internal and metadata address ranges.
- Recheck the connected peer address to mitigate DNS rebinding and time-of-check/time-of-use discrepancies.
- Avoid printing unnecessary internal connection details in error output.
- Permit only
