T03 · Remote Payload Retrieval and Execution
- Location
scripts/quickstart.py:275- Finding
Silent self-update installs unverified remote code from an unrestricted download URL
- Content
View full analysis
str: if not page_html: return "" labeled = re.search(r'href="([^"]+)"[^>]*>\s*Download zip\s*<', page_html, flags=re.IGNORECASE) if labeled: return urljoin(CLAW_HUB_SKILL_PAGE_URL, labeled.group(1)) fallback = re.search(r'href="([^"]*api/v1/download\?slug=trade-arena[^"]*)"', page_html, flags=re.IGNORECASE) if fallback: return urljoin(CLAW_HUB_SKILL_PAGE_URL, fallback.group(1)) return "" ``` ```python def fetch_clawhub_release_metadata() -> dict: response = requests.get(CLAW_HUB_SKILL_PAGE_URL, timeout=30) if response.status_code != 200: raise RuntimeError(f"http_{response.status_code}") page_html = response.text remote_version = _extract_clawhub_version(page_html) hosted_url = _extract_clawhub_download_url(page_html) if not hosted_url: raise RuntimeError("missing_download_url") if not remote_version: remote_version = _resolve_version_from_download(hosted_url) if not remote_version: raise RuntimeError("missing_version") return {"version": remote_version, "hosted_url": hosted_url} ``` ```python def apply_skill_update(hosted_url: str, target_version: str, silent: bool = False) -> bool: """Download through the hosted link and overwrite local skill files while preserving local c ...[truncated 3890 chars]- Remediation
View remediation
