T09 · Insecure Skill Coding Practices
- Location
scripts/utils/validator.js:3- Finding
Unrestricted URL Downloads Enable SSRF and Internal Resource Exfiltration
- Content
View full analysis
{ if (this.__isRequireRedirect(response)) { redirectCount++; if (redirectCount > this.__opts.maxRedirects) { const err = new Error("Too many redirects"); this.__setState(this.__states.FAILED); this.emit("error", err); return reject(err); } const redirectedURL = /^https?:\/\//.test(response.headers.location) ? response.headers.location : new URL(response.headers.location, url).href; this.emit("redirected", redirectedURL, url); return getRequest(redirectedURL, getReqOptions(redirectedURL)); ``` ### Technical Analysis URL validation verifies only that the supplied scheme is HTTP or HTTPS. It does not reject: - Loopback addresses such as `127.0.0.1` and `::1` - Private network ranges - Link-local addresses such as `169.254.0.0/16` - Cloud metadata endpoints - IPv4 addresses encoded in alternative formats - Hostnames that resolve to private or reserved addresses - DNS rebinding - Redirects from public hosts to internal ...[truncated 2168 chars]- Remediation
View remediation
