T09 · Insecure Skill Coding Practices
- Location
scripts/search_laws.py:97- Finding
TLS Certificate and Hostname Verification Disabled for Authenticated API Requests
- Content
View full analysis
Vulnerability Details
File Location:
scripts/search_laws.py, lines 97–114
Vulnerability Type: Improper TLS certificate validation
Risk Level: Highpython req = urllib.request.Request( API_URL, data=payload, headers={ "Content-Type": "application/json", "Authorization": "Bearer " + apikey }, method="POST", ) ctx = ssl.create_default_context() ctx.check_hostname = False ctx.verify_mode = ssl.CERT_NONE try: with urllib.request.urlopen(req, timeout=30, context=ctx) as resp: return json.loads(resp.read().decode("utf-8"))Technical Analysis
The code creates a default TLS context but then explicitly disables both server hostname validation and certificate-chain verification:
ctx.check_hostname = Falsepermits a certificate issued for an unrelated hostname.ctx.verify_mode = ssl.CERT_NONEaccepts certificates that are self-signed, expired, untrusted, or otherwise invalid.
Consequently, HTTPS encrypts the connection without reliably authenticating the remote server. An attacker capable of intercepting or redirecting network traffic can impersonate
platform.delilegal.comusing an arbitrary certificate.The affected request carries two sensitive or integrity-relevant values:
- The configured API key in the
Authorization: Bearerheader. - The user's legal-search query in the JSON request body.
Because the response is also accepted over the unauthenticated connection and formatted as legal-retrieval output, an interceptor can return manipulated legal records that may be presented to the user as database results.
Attack Path
- A user places a valid API key in
config.jsonand invokes the legal-search script. - An attacker gains a position from which traffic can be intercepted or redirected, such as a compromised network gateway, malicious Wi-Fi access point, poisoned DNS resolver, or hostile proxy.
- T ...[truncated 1512 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove the statements that disable TLS validation:
ctx.check_hostname = Falsectx.verify_mode = ssl.CERT_NONE
-
Prefer the standard verified HTTPS behavior:
python try: with urllib.request.urlopen(req, timeout=30) as resp: return json.loads(resp.read().decode("utf-8")) -
If an explicit SSL context is required, retain secure defaults without modifying verification settings:
python ctx = ssl.create_default_context() try: with urllib.request.urlopen(req, timeout=30, context=ctx) as resp: return json.loads(resp.read().decode("utf-8")) -
Treat certificate or hostname validation failures as hard errors. Do not retry using an unverified context or offer an insecure fallback.
-
Ensure the runtime environment has a current trusted CA bundle. If the service requires a private CA, load only that specific trusted CA using
ssl.create_default_context(cafile=...)rather than disabling verification globally. -
Rotate any API key that has previously been transmitted using the vulnerable implementation, especially if the script was used on untrusted networks.
-
Prefer loading the API key from an environment variable or managed secret store instead of a project file. If
config.jsonremains supported, restrict its filesystem permissions and exclude it from version control. -
Add an automated test that connects to a server presenting an invalid or hostname-mismatched certificate and verifies that the request fails.
-
