T09 · Insecure Skill Coding Practices
- Location
scripts/download_file.py:12- Finding
Redirect-Based Server-Side Request Forgery to Private Network Resources
- Content
View full analysis
Vulnerability Details
File Location:
scripts/download_file.py, lines 12–20
Vulnerability Type: Server-Side Request Forgery (SSRF) through unvalidated URLs and redirects
Risk Level: MediumVulnerable code:
python parser = argparse.ArgumentParser() parser.add_argument("url") args = parser.parse_args() DOWNLOAD_DIR.mkdir(parents=True, exist_ok=True) filename = Path(urllib.parse.urlparse(args.url).path).name or "download" destination = DOWNLOAD_DIR / filename with urllib.request.urlopen(args.url) as response: destination.write_bytes(response.read())Technical Analysis
The script passes the supplied URL directly to
urllib.request.urlopen()without validating its scheme, embedded credentials, port, resolved IP address, or redirect destinations.urlopen()follows HTTP redirects by default.This contradicts the safeguard declared in
SKILL.md, which says that local and private-network targets, URL credentials, and unsupported ports are rejected. The implementation performs none of those checks.Even if the initially supplied URL resolves to a public address, its server can return a redirect to a loopback, link-local, or private-network address. The Skill host then requests that internal destination using its own network access. The resulting response is written to a local file.
The attacker-controlled inputs are the public URL server and its redirect responses. The crossed trust boundary is from an untrusted Internet service into network resources accessible only to the Skill host.
Attack Path
- An attacker operates a public HTTP or HTTPS endpoint.
- The user is induced to request a file from that endpoint.
- The endpoint returns an HTTP redirect to a private destination such as a loopback, link-local, or RFC1918 address.
urllib.request.urlopen()automatically follows the redirect without revalidating the destination.- The Skill host accesses the internal ...[truncated 657 chars]
- Remediation
View remediation
Remediation Suggestions
- Accept only explicitly supported
httpandhttpsURLs. - Reject URLs containing user information or unsupported ports.
- Resolve the destination hostname and reject loopback, private, link-local, multicast, unspecified, and reserved addresses.
- Disable automatic redirects and process each redirect explicitly.
- Reapply URL, hostname, port, and resolved-address validation to every redirect hop.
- Limit the number of redirects and prevent scheme changes to unsupported protocols.
- Account for DNS rebinding by connecting only to a previously validated address while preserving the intended HTTP host identity.
- Apply connection and response timeouts.
- Accept only explicitly supported
