T09 · Insecure Skill Coding Practices
- Location
scripts/organize.py:33- Finding
Server-Side Request Forgery Through Unrestricted Bookmark Link Checking
- Content
View full analysis
= 400: return (url, status_code, None) except Exception as e: return (url, None, str(e)) return None ``` ```python if args.check_links: urls_to_check = [link['url'] for link in unique_links] print(f"Checking {len(urls_to_check)} links for availability (this may take several minutes)...") with ThreadPoolExecutor(max_workers=10) as executor: future_to_url = {executor.submit(check_url, url): url for url in urls_to_check} for i, future in enumerate(as_completed(future_to_url)): print(f"Progress: {i + 1}/{len(urls_to_check)}", end='\r', file=sys.stderr) result = future.result() if result: dead_links_report.append(result) ``` ### Technical Analysis When `--check-links` is enabled, every URL imported from the bookmark file is passed to `curl`. The only earlier protocol check is `url.startswith('http')`, which does not prevent access to: - Loopback addresses such as `127.0.0.1` or `[::1]` - Private network ranges - Link-local addresses - Cloud metadata services - Internal hostnames - Nonstandard ports - Public URLs that redirect to internal destinations The `-L` option instructs `curl` to follow redirects. Therefore, validating only the original URL would still be insufficient: an apparently public URL can redirect the request to a protected internal address. The command u ...[truncated 1608 chars]- Remediation
View remediation
