T09 · Insecure Skill Coding Practices
- Location
scripts/media_gen_client.py:114- Finding
Unrestricted Download of Server-Supplied Media URLs
- Content
View full analysis
Dict[str, Any]: """ Download a (possibly signed) URL to local file. Designed for OSS signed URLs returned by video generation tasks. """ os.makedirs(os.path.dirname(out_path) or ".", exist_ok=True) req = urllib.request.Request(url, headers={"User-Agent": "AIsa-Media-Gen/1.0"}) try: with urllib.request.urlopen(req, timeout=timeout_s) as resp, open(out_path, "wb") as f: total = 0 while True: chunk = resp.read(1024 * 1024) # 1MB if not chunk: break f.write(chunk) total += len(chunk) return {"success": True, "saved_to": out_path, "bytes": total} except Exception as e: return {"success": False, "error": str(e), "url": url, "saved_to": out_path} ``` Representative server-controlled call sites include: ```python dl = _download_to_file(urls[0], out_path) ``` ```python dl = _download_to_file(url, out_path) ``` ```python video_url = (resp.get("output") or {}).get("video_url") or (resp.get("output") or {}).get("videoUrl") if video_url: out_path = args.out or _safe_filename("mp4") dl = _download_to_file(video_url, out_path) ``` ### Technical Analysis The image and video generation API can return URLs that the client passes directly to `urllib.request.urlopen`. The implementation does not validate: - The URL scheme - The resolved destination address - Whether the destination is loopback, link-local, private, or otherwise reserved - Redirect destinations - The response content type - The maximum response size - Whether the response a ...[truncated 2687 chars]- Remediation
View remediation
