T09 · Insecure Skill Coding Practices
- Location
schemas/product-import-request.schema.json:58- Finding
Unrestricted Remote Image URLs Enable Server-Side Request Forgery
- Content
View full analysis
Vulnerability Details
File Location:
schemas/product-import-request.schema.json, lines 58–64
Related API Location:openapi.yaml, lines 300–318
Vulnerability Type: Server-Side Request Forgery (SSRF)
Risk Level: HighVulnerable Code
json "images_to_download": { "type": "array", "items": { "type": "string", "format": "uri" } }The corresponding product-import endpoint accepts this field:
yaml /v1/jobs/products/import: post: summary: Create a product import job requestBody: required: true content: application/json: schema: $ref: '#/components/schemas/ProductImportRequest' examples: default: value: {"batch_id": "batch-2026-03-21-01", "items": [{"reference": "NEW-001", "name": {"fr": "Nouveau", "en": "New"}, "price_ht": 10.0, "stock_quantity": 100, "images_to_download": ["https://assets.example.com/img/new-001.jpg"]}], "options": {"create_if_missing": true, "update_if_exists": true, "skip_images_errors": false}}Technical Analysis
The product-import contract permits authenticated clients to supply arbitrary URI values that the asynchronous Bridge worker is expected to download. The schema validates only that each value has the generic
uriformat. It does not restrict the scheme to HTTPS, constrain destination hosts, reject non-public IP address ranges, or specify redirect revalidation.No compensating SSRF controls were identified in the reviewed security and trust documentation. In particular, the contract does not require:
- An allowlist of trusted image hosts
- Rejection of loopback, private, link-local, multicast, or reserved addresses
- Blocking cloud instance-metadata endpoints
- DNS resolution and rebinding protection
- Revalidation of every redirect destination
- Response-size, redirect-count, or download-time limits
Consequently, a user holding the documented
bridge:writepermission may be able to c ...[truncated 1983 chars]- Remediation
View remediation
Remediation Suggestions
-
Restrict accepted schemes
- Permit
httpsonly. - Explicitly reject
file,ftp,gopher,data, and other unsupported schemes. - Enforce the restriction in runtime code rather than relying exclusively on JSON Schema.
- Permit
-
Use a destination allowlist
- Restrict downloads to explicitly approved image hosts or controlled asset domains.
- If arbitrary public hosts are a business requirement, apply strict network-address validation.
-
Block non-public destinations
- Resolve the hostname before connecting.
- Reject loopback, private, link-local, multicast, unspecified, reserved, and documentation address ranges for both IPv4 and IPv6.
- Explicitly block known cloud metadata destinations.
- Connect only to the validated resolved address while preserving correct TLS hostname verification.
-
Prevent DNS rebinding and redirect bypasses
- Guard against DNS answers changing between validation and connection.
- Disable redirects where possible.
- If redirects are required, reapply scheme, hostname, DNS, and IP-range validation to every redirect target.
- Set a small maximum redirect count.
-
Constrain downloaded content
- Set strict connection, read, and total-operation timeouts.
- Enforce a maximum response size while streaming.
- Validate the response
Content-Typeand verify the actual file signature as a supported image. - Reject decompression bombs and images exceeding safe dimension or pixel-count limits.
-
Apply network-level defense in depth
- Run import workers with restricted egress.
- Deny access from the worker network to metadata, management, database, Redis, and other internal service ranges unless explicitly required.
-
Add security tests
- Cover loopback and private IPv4 addresses, IPv6 loopback and unique-local addresses, integer and encoded IP forms, metadata endpoints, DNS rebinding, and redirects to prohibited destinations.
...[truncated 99 chars]
-
