T09 · Insecure Skill Coding Practices
- Location
scripts/media_gen_client.py:107- Finding
Unvalidated API-Provided URLs Permit Arbitrary Resource Downloads
- Content
View full analysis
Dict[str, Any]: """ Download a (possibly signed) URL to local file. Designed for OSS signed URLs returned by video generation tasks. """ os.makedirs(os.path.dirname(out_path) or ".", exist_ok=True) req = urllib.request.Request(url, headers={"User-Agent": "AIsa-Media-Gen/1.0"}) try: with urllib.request.urlopen(req, timeout=timeout_s) as resp, open(out_path, "wb") as f: total = 0 while True: chunk = resp.read(1024 * 1024) # 1MB if not chunk: break f.write(chunk) total += len(chunk) return {"success": True, "saved_to": out_path, "bytes": total} except Exception as e: return {"success": False, "error": str(e), "url": url, "saved_to": out_path} ``` API-provided URLs reach this function without validation: ```python dl = _download_to_file(urls[0], out_path) ``` ```python if kind == "url" and url: dl = _download_to_file(url, out_path) ``` ```python video_url = (resp.get("output") or {}).get("video_url") or (resp.get("output") or {}).get("videoUrl") if video_url: out_path = args.out or _safe_filename("mp4") dl = _download_to_file(video_url, out_path) ``` ### Technical Analysis The client treats media URLs returned by the remote API as trusted and passes them directly to `urllib.request.urlopen`. It does not validate: - The URL scheme - The destination hostname - The resolved IP address - Whether the destination is loopback, private, link-local, or otherwise reserv ...[truncated 2132 chars]- Remediation
View remediation
