T09 · Insecure Skill Coding Practices
- Location
SKILL.md:29- Finding
Public Service Exposure with a Predictable Application Secret
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 29–30 and 42–43
Vulnerability Type: Insecure network configuration and hardcoded placeholder secret
Risk Level: MediumVulnerable Code:
yaml ports: - "8080:8080"yaml server: secret_key: "change-me-to-random-string" bind_address: "0.0.0.0"Technical Analysis
Docker publishes the mapping
8080:8080on all host interfaces by default. The accompanying SearXNG configuration explicitly binds the application to0.0.0.0, making it reachable from external networks wherever host and network firewall rules permit access.The setup also writes a predictable placeholder value into
server.secret_key. Although the value indicates that it should be changed, the provided executable setup neither generates a secure random secret nor prevents deployment with the placeholder. Any security control that relies on this secret may consequently operate with a publicly known value.The documented endpoint uses unencrypted HTTP and does not configure authentication or a TLS reverse proxy. External deployment using the instructions as written can therefore expose search queries and the service itself to unauthorized parties.
Attack Path
- A user copies the documented Docker Compose and SearXNG configuration.
- SearXNG listens on every container network interface because
bind_addressis0.0.0.0. - Docker publishes container port 8080 on every host interface.
- A remote attacker scans for or otherwise discovers the exposed port.
- The attacker directly accesses the unauthenticated search endpoint and submits arbitrary requests.
- The attacker can consume system resources and upstream search capacity. Network intermediaries may also observe plaintext HTTP queries.
- If application functionality relies on
server.secret_key, the known placeholder further weakens the corresponding secret-dependent protections.
I
...[truncated 577 chars]
- Remediation
View remediation
Remediation Suggestions
-
Bind the published Docker port to loopback by default:
yaml ports: - "127.0.0.1:8080:8080" -
Generate a cryptographically secure secret rather than storing a placeholder. For example, generate it with
openssl rand -hex 32and inject it through a protected configuration file or secret-management mechanism. -
Make deployment fail when the placeholder secret remains configured.
-
For remote access, place SearXNG behind an authenticated TLS reverse proxy and restrict access through firewall rules, a VPN, or an explicit IP allowlist.
-
Do not expose the service directly to the public internet.
-
Document that the default HTTP endpoint is suitable only for loopback or another trusted private network.
-
Apply request throttling and resource limits to reduce abuse and denial-of-service risk.
-
