T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/extract_exif.py:84- Finding
Unnecessary Disclosure of Sensitive GPS Metadata
- Content
View full analysis
Vulnerability Details
File Location:
scripts/extract_exif.py, lines 84-89
Vulnerability Type: Excessive access to and disclosure of sensitive location metadata
Risk Level: MediumVulnerable Code:
python # GPS information if 34853 in exif_data: gps_info = {} for key, val in exif_data[34853].items(): gps_info[GPSTAGS.get(key, key)] = val result["gps"] = gps_infoTechnical Analysis
The script extracts all available GPS EXIF fields and includes them in its JSON output. The documented photography workflow requires shooting parameters such as aperture, shutter speed, ISO, focal length, and camera model, but it does not require precise geographical location.
Consequently, the implementation accesses and discloses sensitive metadata beyond the minimum necessary scope. Because the JSON is returned to the Agent, GPS information may enter the conversation context, execution logs, or other downstream records. The audit found no code that transmits this information to an external service, so this is a local over-collection and disclosure issue rather than confirmed network exfiltration.
Attack Path
- A user provides a photograph containing embedded GPS EXIF metadata.
- The Skill invokes
scripts/extract_exif.pywith the photograph path. - Pillow reads the photograph and returns its complete EXIF structure.
- The script identifies EXIF tag
34853and copies every GPS field intogps_info. - The GPS data is serialized into the JSON response under the
gpsproperty. - The Agent runtime, conversation history, or execution logs may retain the disclosed location.
No attacker-controlled privilege escalation is required; the issue occurs during normal processing of a geotagged image.
Impact Assessment
The script can read and expose location metadata already embedded in any image that the invoking user permits it to acce ...[truncated 360 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove GPS extraction because it is unnecessary for the documented photography analysis:
python # Do not extract or return GPS metadata. result = {"has_exif": True, "params": params} return result -
If location analysis becomes a legitimate optional feature, require explicit informed consent before reading or returning GPS fields.
-
Return only an indicator such as
has_gps: trueunless exact coordinates are essential. -
When approximate location is sufficient, round coordinates and omit altitude, timestamp, processing method, and other unnecessary GPS fields.
-
Ensure Agent prompts, diagnostic output, telemetry, and execution logs do not retain precise GPS values.
-
Document all collected EXIF fields and provide users with a privacy warning before processing geotagged photographs.
-
