T09 · Insecure Skill Coding Practices
- Location
scripts/search_cases.py:115- Finding
TLS Certificate and Hostname Verification Disabled
- Content
View full analysis
Vulnerability Details
File Location:
scripts/search_cases.py, lines 115–120
Vulnerability Type: Improper TLS certificate validation
Risk Level: HighVulnerable Code
python ctx = ssl.create_default_context() ctx.check_hostname = False ctx.verify_mode = ssl.CERT_NONE try: with urllib.request.urlopen(req, timeout=30, context=ctx) as resp: return json.loads(resp.read().decode("utf-8"))Technical Analysis
The script creates a TLS context but explicitly disables both certificate-chain verification and hostname verification. Consequently, HTTPS encrypts the connection without authenticating that the remote endpoint is the legitimate Deli Legal API server.
An attacker capable of intercepting or redirecting network traffic can present an arbitrary certificate, which the client will accept. This enables a man-in-the-middle attack against requests sent to the configured API endpoint.
Each affected request contains the API key in the
Authorization: Bearerheader. Requests may also contain sensitive legal-search keywords or full case materials supplied through the--long-textoption. The attacker can read these values and return manipulated API responses that the script will present as legitimate case-search results.Attack Path
- A user invokes the script with a search query or sensitive case material.
- The script reads the API key from
config.jsonand places it in the Bearer authorization header. - An attacker with a network interception or traffic-redirection position redirects or intercepts the connection to the API.
- The attacker presents an untrusted certificate for an attacker-controlled endpoint.
- Because certificate and hostname verification are disabled, the script accepts the certificate.
- The attacker captures the API key and submitted legal material.
- The attacker may return forged JSON responses, causing fabricated or altered legal case information to be displayed as API output.
Im
...[truncated 597 chars]
- Remediation
View remediation
Remediation Suggestions
Remove the statements that disable hostname and certificate verification. Use Python's default verified TLS behavior:
python try: with urllib.request.urlopen(req, timeout=30) as resp: return json.loads(resp.read().decode("utf-8"))Alternatively, retain an explicit default context without weakening its security settings:
python ctx = ssl.create_default_context() try: with urllib.request.urlopen(req, timeout=30, context=ctx) as resp: return json.loads(resp.read().decode("utf-8"))Additional hardening measures:
- Allow certificate-validation failures to terminate the request rather than retrying insecurely.
- If a private certificate authority is required, configure its trusted CA bundle explicitly instead of using
ssl.CERT_NONE. - Store the API key in an environment variable or dedicated secret manager rather than a project file containing operational credentials.
- Rotate any API key that may have been used while verification was disabled.
- Add an automated test confirming that self-signed certificates and hostname mismatches are rejected.
- Avoid logging authorization headers or full legal-case materials in error and diagnostic output.
