T09 · Insecure Skill Coding Practices
- Location
bili-transcript.py:108- Finding
Unrestricted URL Processing Enables Server-Side Request Forgery
- Content
View full analysis
tuple: """Extract aid and cid from a Bilibili video URL""" try: html = http_get(url, timeout=10).decode("utf-8") match = re.search(r'window\.__INITIAL_STATE__=(.*?);\(function', html) if match: data = json.loads(match.group(1)) video_data = data.get("videoData", {}) return video_data.get("aid"), video_data.get("cid") cmd = [*([YT_DLP] if isinstance(YT_DLP, str) else YT_DLP), "--dump-json", "--no-download", url] result = subprocess.run(cmd, capture_output=True, text=True) ``` ```python def fetch_danmaku(url: str, output_dir: Path) -> str: """Download danmaku subtitles via yt-dlp, returns xml file path""" output_template = str(output_dir / "danmaku") cmd = [ *([YT_DLP] if isinstance(YT_DLP, str) else YT_DLP), "--write-subs", "--sub-langs", "danmaku", "--skip-download", "-o", output_template, url, ] result = subprocess.run(cmd, capture_output=True, text=True) ``` ```python def download_audio(url: str, output_dir: str) -> str: """Download audio as m4a via yt-dlp""" output_path = Path(output_dir) / "audio.m4a" cmd = [ *([YT_DLP] if isinstance(YT_DLP, str) else YT_DLP), "-f", "bestaudio[ext=m4a]/bestaudio", "-o", str(output_path), url, ] result = subprocess.run(cmd, capture_output=True, text=True) ``` ### Technical Analysis The command-line interface describes its input as a Bilibili video URL, but the implementation does not enforce that restriction. The supplied value is passed directly to `urllib.req ...[truncated 2769 chars]- Remediation
View remediation
