T09 · Insecure Skill Coding Practices
- Location
voice-ai-tts-sdk.js:178- Finding
Caller-Controlled HTTPS Base URL Can Expose the API Key and Submitted Text
- Content
View full analysis
{ if (value !== undefined && value !== null) { url.searchParams.append(key, value); } }); } const requestOptions = { method, hostname: url.hostname, path: url.pathname + url.search, port: url.port || 443, headers: { 'Authorization': `Bearer ${this.apiKey}`, 'User-Agent': 'VoiceAI-SDK/1.1.4', ...options.headers }, timeout: this.timeout }; ``` ```javascript _streamRequest(method, endpoint, options = {}) { const url = new URL(`/api/${API_VERSION}${endpoint}`, this.baseUrl); if (url.protocol !== 'https:') { throw new ValidationError('Only https baseUrl is supported'); } const requestOptions = { method, hostname: url.hostname, path: url.pathname, port: url.port || 443, headers: { 'Authorization': `Bearer ${this.apiKey}`, 'Content-Type': 'application/json', 'User-Agent': 'VoiceAI-SDK/1.1.4', ...options.headers } }; ``` ### Technical Analysis The SDK accepts an arbitrary `options.baseUrl` and validates only that the resulting URL uses HTTPS. It does not verify that the destination hostname or origin is the intended Voice.ai service, `https://dev.voice.ai`. HTTPS protects a connection against in ...[truncated 2736 chars]- Remediation
View remediation
