T09 · Insecure Skill Coding Practices
- Location
scripts/shein_image_search.py:122- Finding
Unrestricted Remote Image Fetching Enables Server-Side Request Forgery and Data Relay
- Content
View full analysis
Vulnerability Details
File Location:
scripts/shein_image_search.py:122-125, with the vulnerable input routing at lines 158-166 and external upload at lines 213-224
Vulnerability Type: Server-Side Request Forgery (SSRF) and unintended data relay
Risk Level: MediumVulnerable Code
python def _read_remote_image(source, timeout): request = Request(source, headers={"User-Agent": "GeekBI-SHEIN-Research-Skill"}) with urlopen(request, timeout=timeout) as response: data = _read_limited(response) content_type = _validate_image(data, response.headers.get_content_type()) path_name = Path(unquote(urlparse(response.geturl()).path)).name filename = path_name or "image" + _extension(content_type) return data, content_type, filenameThe input dispatcher permits any HTTP or HTTPS URL:
python parsed = urlparse(source) if parsed.scheme in {"http", "https"}: return _read_remote_image(source, timeout) if parsed.scheme not in {"", "file"}: raise ValueError("图片地址只支持本地文件、file、http 或 https") return _read_local_image(source)Successfully fetched content is uploaded to the configured GeekBI endpoint:
python data, content_type, filename = read_image_source(args.image, args.timeout) body, multipart_content_type = build_multipart(data, content_type, filename) payload = authenticated_json_request( build_url(args.base_url, params), args.base_url, args.timeout, method="POST", body=body, headers={"Content-Type": multipart_content_type}, )Technical Analysis
The
--imageoption accepts an arbitrary HTTP or HTTPS URL and passes it directly tourllib.request.urlopen. The implementation does not:- Reject loopback, private, link-local, reserved, multicast, or cloud-metadata IP ranges.
- Resolve and validate the destination address before connecting.
- Revalidate destination addresses ...[truncated 2350 chars]
- Remediation
View remediation
Remediation Suggestions
- Prefer local user-provided files and disable remote URL fetching unless it is strictly necessary.
- If remote fetching is required, maintain an explicit allowlist of approved public image hosts.
- Resolve the hostname before connecting and reject every address in loopback, private, link-local, multicast, unspecified, reserved, and documentation ranges for both IPv4 and IPv6.
- Explicitly block cloud metadata destinations, including link-local metadata addresses and provider-specific metadata hostnames.
- Disable automatic redirects or implement a small redirect limit and repeat full scheme, hostname, DNS, and IP validation for every redirect target.
- Protect against DNS rebinding by connecting only to the validated resolved address while preserving safe TLS hostname verification.
- Permit HTTPS only unless a documented use case requires HTTP.
- Apply outbound network controls at the container or host level so the Skill cannot reach internal networks or metadata services.
- Obtain explicit user confirmation before transmitting a fetched image to GeekBI, especially when the source is not a user-uploaded local file.
- Add tests covering loopback addresses, RFC 1918 ranges, IPv6 local addresses, metadata endpoints, redirects to private hosts, alternate numeric IP formats, and DNS rebinding scenarios.
