T09 · Insecure Skill Coding Practices
- Location
scripts/email-triage.py:153- Finding
Configurable Ollama Endpoint Can Exfiltrate Sensitive Email Content
- Content
View full analysis
", "reason": ""}}""" payload = json.dumps({ "model": OLLAMA_MODEL, "prompt": prompt, "stream": False, "options": { "temperature": 0.1, "num_predict": 100, }, }).encode() try: req = urllib.request.Request( f"{OLLAMA_URL}/api/generate", data=payload, headers={"Content-Type": "application/json"}, ) with urllib.request.urlopen(req, timeout=CLASSIFICATION_TIMEOUT) as resp: result = json.loads(resp.read()) response_text = result.get("response", "").strip() ``` The destination is configured without restrictions: ```python OLLAMA_URL = os.environ.get("OLLAMA_URL", "http://127.0.0.1:11434") ``` ### Technical Analysis For every newly processed unread email, the script inserts the sender, subject, and up to 300 characters of the body preview into an Ollama prompt. It then sends that prompt to the endpoint specified by `OLLAMA_URL`. Although the default endpoint is loopback-only, the configuration accepts an arbitrary URL. The implementation does not: - Restrict the destination to loopback or another trusted allowlist. - Require explicit consent before using a remote endpoint. - Require HTTPS for non-local destinations. - Warn that mailbox content will be transmitted. - Redact sensitive values from the subject, sender, or preview. - Disable redirects to untrusted destinations. Consequently, a malicious or mistakenly supplied environment variable can cause private mailbox content to be sent to an external server. If plain HTTP is used remotely, intermediaries may also intercept or alter the request. The broad exception handler ...[truncated 1544 chars]- Remediation
View remediation
