T09 · Insecure Skill Coding Practices
- Location
scripts/collect.py:66- Finding
Server-Side Request Forgery Through Substring-Based Domain Validation
- Content
View full analysis
"{}|\\^`\[\]]+' urls = re.findall(url_pattern, text) for url in urls: if any(domain in url for domain in SUPPORTED_DOMAINS): return url return None ``` The accepted URL is passed to these request sinks: ```python resp = requests.get(url, headers=HEADERS, timeout=15, allow_redirects=True) ``` ### Technical Analysis The code determines whether a URL is permitted by checking whether a supported domain string occurs anywhere in the complete URL. It does not parse the URL and verify its actual hostname. An attacker can therefore place an allowed string in the path, query string, user-information component, or an attacker-controlled hostname. Examples that satisfy the substring check include: ```text http://127.0.0.1/admin?toutiao.com http://169.254.169.254/latest/meta-data/?mp.weixin.qq.com https://toutiao.com.attacker.example/article ``` In addition, `allow_redirects=True` permits an initially accepted URL to redirect to a loopback, private-network, link-local, or cloud metadata address. Redirect destinations are not revalidated. The fetched response is parsed as article content. That content can subsequently be transmitted to DeepSeek for analysis and represented in a Feishu record. Consequently, this issue can combine unauthorized internal resource access with external disclosure of retrieved information. This behavior exceeds the minimum network privileges required by the declared functionality, which only needs to retrieve articles from a small set of documented public domains. ### Attack Path 1. An attacker sends the agent a message containing a crafted HTTP or HTTPS URL. 2. The URL i ...[truncated 1281 chars]- Remediation
View remediation
