T09 · Insecure Skill Coding Practices
- Location
scripts/render_kroki.py:49- Finding
Unconditional Disclosure of Diagram Source to a Remote Rendering Service
- Content
View full analysis
bytes: req = urllib.request.Request(url, data=body, method="POST") req.add_header("User-Agent", "Mozilla/5.0 (compatible; render_kroki/1.0)") for k, v in (headers or {}).items(): req.add_header(k, v) with urllib.request.urlopen(req, timeout=timeout) as resp: return resp.read() def render_via_kroki( diagram_type: str, output_format: str, source: str, kroki_url: str, *, use_json: bool = False, ) -> bytes: base = kroki_url.rstrip("/") if use_json: payload = json.dumps({ "diagram_source": source, "diagram_type": diagram_type, "output_format": output_format, }) return http_post( base + "/", payload.encode("utf-8"), headers={"Content-Type": "application/json"}, ) url = f"{base}/{diagram_type}/{output_format}" accept = FORMAT_ACCEPT.get(output_format, "") headers = {"Content-Type": "text/plain; charset=utf-8"} if accept: headers["Accept"] = accept return http_post(url, source.encode("utf-8"), headers=headers) ``` ```python parser.add_argument( "--kroki-url", default=os.environ.get("KROKI_URL", "https://kroki.io"), help="Kroki base URL", ) ``` ```python source = read_source(args.input_path) if output_format == "html": if diagram_type == "mermaid" and not args.json: html = mermaid_html_template(source, title=args.title) data = html.encode("utf-8") else: svg_bytes = render_via_kroki( diagram_type, "svg", source, ...[truncated 2822 chars]- Remediation
View remediation
