T09 · Insecure Skill Coding Practices
- Location
lib/convertkit-api.sh:35- Finding
ConvertKit API Secret Exposed in URL Query Parameters
- Content
View full analysis
Vulnerability Details
File Location:
lib/convertkit-api.sh:35andlib/convertkit-api.sh:62-66
Vulnerability Type: Sensitive credential exposure through request URLs
Risk Level: MediumVulnerable Code
bash # List all sequences convertkit_list_sequences() { check_convertkit_auth || return 1 curl -s "$CONVERTKIT_API_BASE/sequences?api_secret=$CONVERTKIT_API_SECRET" }bash # Get sequence subscribers convertkit_get_subscribers() { local sequence_id="$1" check_convertkit_auth || return 1 curl -s "$CONVERTKIT_API_BASE/sequences/$sequence_id/subscriptions?api_secret=$CONVERTKIT_API_SECRET" }Technical Analysis
The ConvertKit API secret is embedded directly in URL query parameters. Although HTTPS protects the URL while it travels over the network, complete URLs can still be exposed through local process inspection, HTTP proxy logs, diagnostic traces, server access logs, monitoring platforms, or shell debugging output.
Query parameters are generally unsuitable for long-lived credentials because URL handling infrastructure commonly records them. The affected functions are invoked by connection testing and sequence monitoring operations.
Attack Path
- A user exports a valid
CONVERTKIT_API_SECRET. - The user runs the monitoring script or calls one of the affected wrapper functions.
- The secret is inserted into the complete
curlURL. - A local observer, proxy, debugging facility, or request-logging system records that URL.
- An attacker extracts the secret from the recorded URL.
- The attacker reuses the credential against the ConvertKit API.
Impact Assessment
An exposed API secret can permit unauthorized ConvertKit API operations within the privileges granted to that credential. Potential scope includes viewing sequence and subscriber information and performing supported account-level sequence or subscriber operations.
Thi ...[truncated 144 chars]
- A user exports a valid
- Remediation
View remediation
Remediation Suggestions
- Use ConvertKit's supported authorization-header mechanism where available.
- If the API version requires body-based authentication, place the secret in the HTTPS request body instead of the URL.
- Avoid verbose shell tracing and HTTP debugging around authenticated requests.
- Ensure logs redact authorization values and known secret fields.
- Use a narrowly scoped credential if the platform supports scopes.
- Rotate any API secret that may already have appeared in process telemetry or logs.
