T09 · Insecure Skill Coding Practices
- Location
scripts/generate_podcast.py:158- Finding
Authentication Credentials Can Be Sent to an Untrusted WebSocket Endpoint
- Content
View full analysis
Vulnerability Details
File Location:
scripts/generate_podcast.py, lines 158-166, 225-231, and 268-272
Vulnerability Type: Unrestricted credential-bearing endpoint configuration
Risk Level: HighVulnerable Code
python def __init__( self, appid: str, access_token: str, app_key: str = "aGjiRDfUWi", resource_id: str = DEFAULT_RESOURCE_ID, endpoint: str = ENDPOINT, ): self.appid = appid self.access_token = access_token self.app_key = app_key self.resource_id = resource_id self.endpoint = endpointpython headers = { "X-Api-App-Id": self.appid, "X-Api-App-Key": self.app_key, "X-Api-Access-Key": self.access_token, "X-Api-Resource-Id": self.resource_id, "X-Api-Connect-Id": str(uuid.uuid4()), }python websocket = await websockets.connect( self.endpoint, additional_headers=headers )Technical Analysis
PodcastGeneratorexposesendpointas a caller-controlled constructor argument. The value is passed directly towebsockets.connect()without validating its scheme, hostname, port, or relationship to the expected Volcengine service.The connection includes the Volcengine App ID, App Key, access token, resource ID, and connection ID as HTTP headers. After the connection is established, the requested podcast text is also sent in the session payload. Consequently, an attacker-controlled endpoint can collect both authentication material and user-supplied content.
WebSocket TLS does not mitigate this issue when the attacker owns a domain with a valid certificate. TLS would secure the connection to the attacker rather than verify that the recipient is the intended Volcengine service.
Attack Path
- An attacker influences application code or configuration that constructs
PodcastGenerator. - The attacker supplies an endpoint such as
wss://attacker.example/ws.
...[truncated 969 chars]
- An attacker influences application code or configuration that constructs
- Remediation
View remediation
Remediation Suggestions
- Remove endpoint configurability if custom PodcastTTS endpoints are not a required feature.
- Otherwise, parse and normalize the endpoint before connecting and enforce:
- The
wssscheme. - An explicit hostname allowlist, such as
openspeech.bytedance.com. - The expected port.
- No URL user information.
- No IP literals or loopback, private, link-local, and reserved addresses.
- The
- Do not forward authentication headers across redirects or endpoint changes.
- Separate credential-bearing production connections from any custom endpoint or test functionality.
- Fail closed when validation is inconclusive.
- Rotate any credentials that may previously have been used with an untrusted endpoint.
- Add tests proving that alternate domains, deceptive subdomains, plain
wsURLs, IP addresses, and malformed URLs are rejected.
