T09 · Insecure Skill Coding Practices
- Location
scripts/FreeMobile_sms.py:24- Finding
Sensitive API Credentials Transmitted in URL Query Parameters
- Content
View full analysis
Vulnerability Details
File Location:
scripts/FreeMobile_sms.py, lines 24–41
Vulnerability Type: Sensitive information exposure through URL query parameters
Risk Level: MediumVulnerable Code
python url = "https://smsapi.free-mobile.fr/sendmsg" # Limite de longueur SMS if len(message) > 160: print(f"Avertissement: message tronqué à 160 caractères", file=sys.stderr) message = message[:160] params = { 'user': user, 'pass': api_key, 'msg': message } try: response = requests.get(url, params=params, timeout=timeout)Technical Analysis
The
requests.get()call serializesuser,pass, andmsginto the request URL. Consequently, the Free Mobile subscriber identifier, API key, and SMS content become part of the URL query string.HTTPS encrypts the URL while it is transmitted between the client and the HTTPS endpoint, but it does not prevent the complete URL from being retained by local HTTP debugging, application telemetry, exception-reporting systems, forward proxies, or server-side access logs. The bundled API reference explicitly states that the endpoint supports POST requests, so transmitting these sensitive values in the URL is unnecessary.
Exploitation requires access to infrastructure or diagnostics that capture complete request URLs. This finding does not establish that such logging currently exists, but the chosen request method unnecessarily expands the locations in which credentials may be exposed.
Attack Path
- A user invokes the Skill with valid
FREEMOBILE_SMS_USERandFREEMOBILE_SMS_API_KEYenvironment variables. - The script inserts those credentials and the message into query parameters.
requests.get()constructs a URL containinguser,pass, andmsg.- A logging, monitoring, debugging, proxy, or server component records the complete request URL.
- An attacker with access to those records extracts the subsc ...[truncated 638 chars]
- A user invokes the Skill with valid
- Remediation
View remediation
Remediation Suggestions
Use the API's supported POST method so credentials and message content are not embedded in the URL:
python response = requests.post( url, data={ "user": user, "pass": api_key, "msg": message, }, timeout=timeout, )In addition:
- Configure application, HTTP client, proxy, and observability tooling to redact
user,pass, andmsg. - Never print or include the API key in exception messages or diagnostic output.
- Rotate the Free Mobile API key if a URL containing it may already have been logged.
- Restrict access to historical proxy, telemetry, and server logs and apply appropriate retention controls.
- Add a regression test confirming that credentials do not appear in the requested URL.
- Configure application, HTTP client, proxy, and observability tooling to redact
