T09 · Insecure Skill Coding Practices
- Location
videocut/talk-edit/scripts/review_server.js:31- Finding
Unauthenticated Review Server Exposes Local Project Files and Video-Cutting Operations
- Content
View full analysis
{ // CORS res.setHeader("Access-Control-Allow-Origin", "*"); res.setHeader("Access-Control-Allow-Methods", "GET, POST, OPTIONS"); res.setHeader("Access-Control-Allow-Headers", "Content-Type"); // API: execute cut if (req.method === "POST" && req.url === "/api/cut") { let body = ""; req.on("data", (chunk) => (body += chunk)); req.on("end", () => { try { const deleteList = JSON.parse(body); fs.writeFileSync( "delete_segments.json", JSON.stringify(deleteList, null, 2) ); const scriptPath = path.join(__dirname, "cut_video.sh"); execFileSync( "bash", [scriptPath, VIDEO_FILE, "delete_segments.json", outputFile], { stdio: "inherit" } ); // ... } }); return; } // Static file service from the entire current directory const baseDir = path.resolve("."); let filePath = req.url === "/" ? "/review.html" : req.url; filePath = path.resolve("." + filePath); // ... const stream = fs.createReadStream(filePath); stream.pipe(res); }); server.listen(PORT, () => { // ... }); ``` ### Technical Analysis Calling `server.listen(PORT)` without specifying a loopback address normally binds the Node.js HTTP server to the unspecified address, potentially exposing it on all available network interfaces. The server has no authentication, session token, origin validation, or request authorization. The static-file route exposes every readable file beneath the process's current working directory rather than an explicit allowlist such as `review.html`, `audio.mp3`, and the selected video. If the serve ...[truncated 2037 chars]- Remediation
View remediation
{ console.log(`Review server: http://127.0.0.1:${PORT}`); }); ``` 2. Remove wildcard CORS. Prefer no CORS header for a same-origin application. If cross-origin access is necessary, allow only a specific trusted origin. 3. Generate a cryptographically random session token at startup and require it on every API request. 4. Serve only explicit files through dedicated routes. Do not map arbitrary URLs to the current working directory. 5. Add a strict request-body limit and reject the connection when it is exceeded. 6. Validate that `deleteList` is an array of bounded objects containing finite numeric `start` and `end` values. 7. Reject overlapping, negative, non-finite, excessively large, or out-of-duration ranges. 8. Add operation locking and rate limiting so only one cut operation can execute at a time. 9. Run media processing with restricted filesystem permissions and from a dedicated working directory containing no credentials. ]]>
