T09 · Insecure Skill Coding Practices
- Location
scripts/eqxiu_store.py:47- Finding
Unbounded Network Request and Unsafe API Response Handling
- Content
View full analysis
Vulnerability Details
File Location:
scripts/eqxiu_store.py, lines 47–50
Vulnerability Type: Missing request timeout, HTTP status validation, response-size control, schema validation, and exception handling
Risk Level: Mediumpython res = session.post(url=eqxiustore_search_url, json=jsonquery) res.encoding = "utf-8" result = json.loads(res.text) if result["obj"]["total"] == 0:Technical Analysis
The outbound HTTPS request does not define connection or read timeouts. Consequently, the process can wait indefinitely if the fixed external API accepts a connection but responds slowly or never completes its response.
The implementation also parses the response without calling
raise_for_status(), limiting the response size, or validating its structure. A malformed response, non-JSON error page, oversized body, or JSON document without the expectedobj.totalfields can therefore cause excessive resource consumption or unhandled exceptions.Exploitation requires influence over the external service response or the network path. The fixed HTTPS endpoint and certificate verification provided by
requestsreduce arbitrary interception risk, but do not protect against service compromise, service malfunction, or availability failures.Attack Path
- A user invokes the template-search script.
- The script sends a POST request to
https://msearch-api.eqxiu.com/m/search/searchProducts. - The remote service or affected network path delays the response indefinitely, returns an oversized body, returns invalid JSON, or omits expected fields.
- Because no timeout or response checks are present, the process hangs, consumes unnecessary memory, or raises an unhandled exception.
- The current template-search and dependent agent workflow become unavailable.
Impact Assessment
The issue can cause denial of service for the current script process or agent workflow. An oversized response may also increase memory consumption. No evidence in ...[truncated 239 chars]
- Remediation
View remediation
Remediation Suggestions
- Configure explicit connection and read timeouts, for example:
python res = session.post( url=eqxiustore_search_url, json=jsonquery, timeout=(5, 15), ) - Call
res.raise_for_status()before parsing the response. - Catch
requests.Timeout,requests.RequestException, JSON decoding errors, and schema-validation failures, then return a controlled error. - Enforce a maximum response size before loading the complete body into memory.
- Validate that the decoded value is an object and that
obj,total, anddataListhave the expected types before indexing them. - Constrain
pageNoandpageSizeto reasonable positive ranges to reduce unnecessary upstream load and oversized responses. - Avoid replacing detected response encoding unconditionally unless the API contract guarantees UTF-8.
- Configure explicit connection and read timeouts, for example:
