T09 · Insecure Skill Coding Practices
- Location
weibo_favorites_4skill.py:508- Finding
Browser-context cookies can be exfiltrated through attacker-controlled media URLs
- Content
View full analysis
bool: try: # This obtains every cookie available in the browser context. cookies = await context.cookies() cookie_str = "; ".join([f"{c['name']}={c['value']}" for c in cookies]) headers = { "Referer": "https://weibo.com/", "Cookie": cookie_str, } if user_agent: headers["User-Agent"] = user_agent timeout = aiohttp.ClientTimeout(total=timeout_ms / 1000) async with aiohttp.ClientSession(timeout=timeout) as session: async with session.get(video_url, headers=headers) as response: if response.status != 200: print(f"视频下载失败(HTTP {response.status}): {video_url}") return False downloaded_size = 0 with open(target_path, 'wb') as f: async for chunk in response.content.iter_chunked(8192): if chunk: f.write(chunk) downloaded_size += len(chunk) print(f"✓ 视频下载成功: {target_path.name} ({d ...[truncated 2634 chars]- Remediation
View remediation
