T05 · Unauthorized Access and Privilege Escalation
- Location
web/server.py:397- Finding
Unauthenticated Cross-Origin Access to Local Todo Data and Mutation APIs
- Content
View full analysis
Vulnerability Details
File Location:
web/server.py:397-417, 459-468, 495-824
Vulnerability Type: Missing API authentication and permissive cross-origin resource sharing
Risk Level: HighVulnerable Code
python def _json(self, code, obj): body = json.dumps(obj, ensure_ascii=False).encode("utf-8") self.send_response(code) self.send_header("Content-Type", "application/json; charset=utf-8") self.send_header("Content-Length", str(len(body))) self.send_header("Access-Control-Allow-Origin", "*") self.end_headers() self.wfile.write(body) def _read_body(self): length = int(self.headers.get("Content-Length") or 0) if length <= 0: return {} raw = self.rfile.read(length) try: return json.loads(raw.decode("utf-8")) or {} except Exception: return {}python def do_POST(self): path = urlparse(self.path).path if path == "/api/todos": self._api_create(self._read_body()) elif path == "/api/todos/apply-patches": self._api_apply_patches(self._read_body()) elif path == "/api/workspace/open": self._api_workspace_open(self._read_body()) elif path in ("/api/workspace/editor", "/api/workspace/cursor"): self._api_workspace_editor(self._read_body()) else: self._json(404, {"error": "not found"})Technical Analysis
The loopback HTTP service does not authenticate requests, does not validate the
Originheader, and returnsAccess-Control-Allow-Origin: *for JSON API responses.The body parser also accepts JSON regardless of the request's declared content type. Consequently, an attacker-controlled website can send a CORS-simple
POSTrequest withContent-Type: text/plainand a JSON-encoded body. This avoids the preflight that would ordinarily be triggered byapplication/json, while_read_body()still parses the request as JSO ...[truncated 2259 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the wildcard CORS header. For a same-origin local application, do not enable CORS at all.
- Validate
OriginandHostagainst an exact allowlist containing only the service's expected loopback origin and port. - Generate an unguessable authentication or CSRF token when the server starts and require it on every API request.
- Set the token through a secure initialization mechanism rather than exposing it in broadly readable API responses.
- Require
Content-Type: application/jsonfor JSON endpoints and reject all other media types with HTTP 415. - Add explicit request authorization checks to every read and mutation endpoint, including workspace-opening endpoints.
- Consider rejecting browser requests with missing or unexpected
Sec-Fetch-Sitemetadata as defense in depth. - Apply request-size limits before reading request bodies.
- Keep the default loopback binding and warn or require explicit confirmation when the user selects a non-loopback
--host.
