T09 · Insecure Skill Coding Practices
- Location
openalexandria_cli.py:13- Finding
Bearer credentials and submission data can be transmitted to an arbitrary or insecure endpoint
- Content
View full analysis
str: return os.environ.get("OPENALEXANDRIA_BASE_URL", DEFAULT_BASE).rstrip("/") def http_json(method: str, url: str, payload=None, api_key: str | None = None): data = None headers = {"Accept": "application/json"} if api_key: headers["Authorization"] = f"Bearer {api_key}" if payload is not None: raw = json.dumps(payload).encode("utf-8") data = raw headers["Content-Type"] = "application/json; charset=utf-8" req = urllib.request.Request(url, data=data, method=method, headers=headers) try: with urllib.request.urlopen(req, timeout=30) as resp: body = resp.read().decode("utf-8") ``` Affected authenticated operations include: ```python def cmd_whoami(args): api_key = args.api_key or DEFAULT_API_KEY if not api_key: raise SystemExit("Missing API key. Set OPENALEXANDRIA_API_KEY or pass --api-key.") url = base_url() + "/v1/whoami" return http_json("GET", url, api_key=api_key) ``` ```python def cmd_submit(args): if args.file: with open(args.file, "r", encoding="utf-8") as f: payload = json.load(f) else: payload = json.load(sys.stdin) api_key = args.api_key or DEFAULT_API_KEY if not api_key: raise SystemExit("Missing API key. Set OPENALEXANDRIA_API_KEY or pass --api-key.") url = base_url() + "/v1/submit" return http_json("POST", url, payload=payload, api_key=api_key) ``` ### Technical Analysis `OPENALEXANDRIA_BASE_URL` is used as the destination for all requests without validating its scheme, hostname, port, embedded user information, or trust relationship. Authenticated command ...[truncated 2079 chars]- Remediation
View remediation
