T09 · Insecure Skill Coding Practices
- Location
scripts/playwright-simple.js:12- Finding
Unrestricted Browser Navigation Enables Server-Side Request Forgery
- Content
View full analysis
'); process.exit(1); } (async () => { console.log('🚀 啟動 Playwright 簡單版爬蟲...'); const startTime = Date.now(); const browser = await chromium.launch({ headless: process.env.HEADLESS !== 'false' }); const page = await browser.newPage(); console.log(`📱 導航到: ${url}`); await page.goto(url, { waitUntil: 'domcontentloaded' }); console.log(`⏳ 等待 ${waitTime}ms...`); await page.waitForTimeout(waitTime); // 擷取基本資訊 const result = await page.evaluate(() => { return { title: document.title, url: window.location.href, content: document.body.innerText.substring(0, 5000), metaDescription: document.querySelector('meta[name="description"]')?.content || '', }; }); ``` The stealth implementation follows the same unrestricted navigation pattern and returns extracted page data: ```javascript const url = process.argv[2]; const response = await page.goto(url, { waitUntil: 'domcontentloaded', timeout: 30000, }); const result = await page.evaluate(() => { return { title: document.title, url: window.location.href, htmlLength: document.documentElement.outerHTML.length, contentPreview: document.body.innerText.substring(0, 1000), }; }); ``` ### Technical Analysis All three scraper implementations accept a URL directly from a command-line argument and navigate to it without validating: - The URL scheme - The requested hostname - The resolved ...[truncated 2188 chars]- Remediation
View remediation
