T09 · Insecure Skill Coding Practices
- Location
SKILL.md:24- Finding
Public Service Exposure with a Predictable Server Secret
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 24-38
Vulnerability Type: Insecure network configuration and hardcoded placeholder secret
Risk Level: MediumVulnerable Code
yaml services: searxng: image: searxng/searxng:latest container_name: searxng ports: - "8080:8080" volumes: - ./searxng:/etc/searxng:rw environment: - SEARXNG_BASE_URL=http://localhost:8080/ restart: unless-stoppedyaml server: secret_key: "change-me-to-random-string" bind_address: "0.0.0.0" port: 8080Technical Analysis
The documented Docker configuration publishes container port 8080 on every host interface because no loopback address is specified. SearXNG is also explicitly configured to bind to
0.0.0.0. Consequently, a user who copies this configuration may expose the service to other systems on the local network or, where firewall and routing rules permit, the Internet.The configuration additionally provides a known placeholder value for
secret_key. If the user does not replace it, any security mechanism that depends on this secret's unpredictability may be weakened. The exact consequences depend on the installed SearXNG version and enabled features; the documentation alone does not establish that this secret directly grants authentication bypass.Attack Path
- A user copies the documented configuration without changing its defaults.
- Docker publishes port 8080 on all host interfaces, and SearXNG listens on all container interfaces.
- An attacker discovers the reachable service through network scanning or knowledge of the host address.
- The attacker submits requests to the exposed search endpoint, consuming service and upstream search-engine resources.
- If any enabled feature relies on the configured server secret, the known placeholder may facilitate attacks against that feature.
Impact Assessment
...[truncated 403 chars]
- Remediation
View remediation
Remediation Suggestions
-
Publish the service only on loopback by default:
yaml ports: - "127.0.0.1:8080:8080" -
Generate a cryptographically random secret rather than documenting a reusable value, for example:
bash openssl rand -hex 32 -
Clearly require users to replace the placeholder before startup and prevent deployment when the default value remains.
-
For remote access, place SearXNG behind a properly configured reverse proxy with TLS, authentication, request throttling, and network access controls.
-
Restrict inbound port 8080 using host firewall or cloud security-group rules.
-
Document that
0.0.0.0and unrestricted Docker port publishing are unsuitable defaults for an otherwise local deployment.
-
