T09 · Insecure Skill Coding Practices
- Location
scripts/location.py:89- Finding
Plaintext HTTP Transport for Geolocation Lookup
- Content
View full analysis
Vulnerability Details
File Location:
scripts/location.py, line 89
Vulnerability Type: Plaintext transmission of geolocation queries and responses
Risk Level: MediumVulnerable Code
python url = "http://ip-api.com/json/" if ip is None else f"http://ip-api.com/json/{quote(ip)}"Technical Analysis
The third geolocation fallback communicates with
ip-api.comover unencrypted HTTP. Unlike the first two providers, this connection provides neither transport confidentiality nor reliable server authentication and response integrity.A network-positioned attacker can observe queried IP addresses or modify the JSON response in transit. The application accepts a response when its
statusfield equals"success", normalizes its values, and subsequently prints the provider-controlled location fields without integrity verification.Attack Path
- The first two HTTPS providers fail, are unavailable, or return unusable results.
- The application invokes the third fallback through plaintext HTTP.
- An attacker with a suitable network position intercepts the HTTP request.
- The attacker returns modified JSON containing
"status": "success"and attacker-selected location values. - The application trusts, normalizes, and displays the forged country, region, city, coordinates, postal code, and timezone.
Impact Assessment
The issue does not grant local code execution, additional operating-system privileges, or persistent access. Its scope is limited to the third fallback's network traffic and resulting output.
An attacker can learn the explicitly queried IP address and manipulate geolocation results. Forged values may mislead users or downstream processes that consume JSON output. Provider-controlled strings also reach terminal output, although no concrete terminal escape exploit was established during this audit.
- Remediation
View remediation
Remediation Suggestions
- Replace the plaintext endpoint with an HTTPS-capable geolocation API.
- If the provider cannot support HTTPS, remove this fallback rather than downgrading transport security.
- Require HTTPS for every outbound provider request and reject redirects that downgrade from HTTPS to HTTP.
- Validate the response schema and expected data types before using returned fields.
- Apply length limits and strip control characters from externally supplied strings before rendering human-readable terminal output.
- Add tests confirming that every configured provider URL uses HTTPS and that transport downgrades are rejected.
