T09 · Insecure Skill Coding Practices
- Location
scripts/gaokao_toolkit.py:91- Finding
Unrestricted URL Retrieval Enables Server-Side Request Forgery
- Content
View full analysis
Vulnerability Details
File Location:
scripts/gaokao_toolkit.py, lines 91-98
Vulnerability Type: Server-Side Request Forgery (SSRF)
Risk Level: Mediumpython def fetch_snapshot(args: argparse.Namespace) -> None: out_dir = Path(args.out) out_dir.mkdir(parents=True, exist_ok=True) req = urllib.request.Request(args.url, headers={"User-Agent": "gaokao-volunteer-research/0.3"}) with urllib.request.urlopen(req, timeout=args.timeout) as resp: body = resp.read() content_type = resp.headers.get("content-type", "")Technical Analysis
The
snapshotcommand passes the user-controlledargs.urldirectly tourllib.request.urlopen. The implementation does not:- Restrict requests to HTTPS.
- Enforce an allowlist of official education or government domains.
- Reject loopback, private, link-local, multicast, or reserved IP addresses.
- Revalidate the destination after DNS resolution.
- Validate redirect targets.
- Prevent access to cloud metadata endpoints or local administrative services.
The source policy recommends official sources, but this is a documentation-level control and is not enforced by the executable implementation. Consequently, anyone capable of influencing the snapshot URL can use the Agent's network position to request resources that may not be reachable from the attacker's own system.
Attack Path
- An attacker presents a malicious URL as an admissions policy, score table, or university charter source.
- The Agent invokes:
bash python3 scripts/gaokao_toolkit.py snapshot --url ATTACKER_CONTROLLED_URL ... - The supplied URL points directly to an internal service, loopback interface, private address, or metadata endpoint, or redirects to one.
urlopensends the request using the Agent host's network identity and reachability.- The response is read and saved as a snapshot in the selected research directory.
...[truncated 600 chars]
- Remediation
View remediation
Remediation Suggestions
- Permit only
httpsURLs by default and reject unsupported schemes. - Resolve the destination hostname before connecting and reject loopback, private, link-local, multicast, unspecified, and reserved IP ranges for both IPv4 and IPv6.
- Repeat destination validation after every redirect and limit the number of redirects.
- Consider allowlisting recognized government, examination-authority, CHSI, and university domains.
- Require explicit user confirmation or an administrative override for destinations outside the allowlist.
- Protect against DNS rebinding by connecting only to the validated address while preserving correct TLS hostname verification.
- Record rejected destinations and validation reasons in structured audit output.
- Apply network-level egress controls as defense in depth, especially blocking cloud metadata and internal management networks.
- Permit only
