T09 · Insecure Skill Coding Practices
- Location
voice-ai-tts-sdk.js:173- Finding
Voice.ai API Credential Can Be Redirected to an Arbitrary HTTPS Host
- Content
View full analysis
{ if (value !== undefined && value !== null) { url.searchParams.append(key, value); } }); } const requestOptions = { method, hostname: url.hostname, path: url.pathname + url.search, port: url.port || 443, headers: { 'Authorization': `Bearer ${this.apiKey}`, 'User-Agent': 'VoiceAI-SDK/1.1.5', ...options.headers }, timeout: this.timeout }; ``` The streaming transport follows the same pattern: ```javascript _streamRequest(method, endpoint, options = {}) { const url = new URL(`/api/${API_VERSION}${endpoint}`, this.baseUrl); if (url.protocol !== 'https:') { throw new ValidationError('Only https baseUrl is supported'); } const requestOptions = { method, hostname: url.hostname, path: url.pathname, port: url.port || 443, headers: { 'Authorization': `Bearer ${this.apiKey}`, ...[truncated 2639 chars]- Remediation
View remediation
