T09 · Insecure Skill Coding Practices
- Location
lib/http.js:12- Finding
Bearer Token Can Be Transmitted to an Arbitrary Configured Endpoint
- Content
View full analysis
({ ...currentConfig, endpointUrl: normalizedEndpointUrl, })); outputPayload({ success: true, configPath, endpointUrl: normalizedEndpointUrl, }, options, (payload) => { printKeyValues(payload); }); } ``` ### Technical Analysis Authenticated network communication is necessary for the declared Aqara API functionality. However, the implementation treats `AQARA_ENDPOINT_URL` and the value accepted by `aqara config set-endpoint` as trusted without validating their protocol, hostname, port, or relationship to an approved Aqara API domain. Every network-backed operation then attaches the configured bearer token to this endpoint. Consequently, anyone able to influence t ...[truncated 2166 chars]- Remediation
View remediation
