T09 · Insecure Skill Coding Practices
- Location
scripts/weather.py:24- Finding
HTTPS Certificate and Hostname Verification Disabled
- Content
View full analysis
Vulnerability Details
File Location:
scripts/weather.py, lines 24–29
Vulnerability Type: Improper TLS certificate validation
Risk Level: MediumVulnerable Code
python ctx = ssl.create_default_context() ctx.check_hostname = False ctx.verify_mode = ssl.CERT_NONE req = urllib.request.Request(url) with urllib.request.urlopen(req, timeout=10, context=ctx) as resp: data = json.loads(resp.read().decode())Technical Analysis
The script creates a default TLS context but then explicitly disables both hostname verification and certificate verification. Consequently, the HTTPS connection does not authenticate the identity of
wttr.in.An attacker capable of intercepting the connection can present an arbitrary certificate and impersonate the weather service. The script will accept the connection, decode the response, parse it as JSON, and either print the complete response or extract weather fields from it.
The response is treated as data rather than executable code, so the reviewed implementation does not provide a demonstrated remote-code-execution path. Nevertheless, disabling TLS validation compromises the authenticity and integrity guarantees expected from HTTPS.
Attack Path
- A user invokes the Skill to obtain weather information.
- The script constructs an HTTPS URL for
wttr.in. - An attacker with a network interception position redirects or intercepts the connection.
- The attacker presents a certificate that would ordinarily fail trust or hostname validation.
- Because the script sets
check_hostnametoFalseandverify_modetossl.CERT_NONE, it accepts the attacker's endpoint. - The attacker returns crafted JSON matching, or partially matching, the expected response structure.
- The script parses and displays the attacker-controlled weather data. A malformed or excessively large response may also trigger processing errors or consume resources.
Impact Assessment
An on-path attacker can comprom ...[truncated 553 chars]
- Remediation
View remediation
Remediation Suggestions
Remove the insecure TLS context configuration and rely on Python's platform-default certificate and hostname validation:
python req = urllib.request.Request(url) with urllib.request.urlopen(req, timeout=10) as resp: data = json.loads(resp.read().decode())If an explicit context is required, retain the secure defaults without modifying
check_hostnameorverify_mode:python ctx = ssl.create_default_context() req = urllib.request.Request(url) with urllib.request.urlopen(req, timeout=10, context=ctx) as resp: data = json.loads(resp.read().decode())Additionally:
- Handle certificate-validation failures as hard errors; do not silently retry with verification disabled.
- Limit the number of response bytes read before JSON parsing to reduce denial-of-service risk from oversized responses.
- Validate the returned JSON structure and expected field types before formatting it.
- Add automated tests confirming that untrusted certificates and hostname mismatches are rejected.
