T09 · Insecure Skill Coding Practices
- Location
scraper.js:17- Finding
Insufficient URL Validation Allows Navigation to Untrusted Hosts
- Content
View full analysis
.html`. It does not parse the URL or verify its scheme, hostname, port, credentials, or resolved network address. Consequently, URLs such as the following satisfy the validation rule despite not belonging to 1688: ```text http://127.0.0.1:8080/offer/1.html http://192.168.1.10/offer/1.html https://attacker.example/offer/123.html ``` The current `scraper.js` implementation only creates an output directory and returns a `ready` result; it does not itself invoke `browser.open()`. However, the documented skill workflow explicitly opens the original URL after applying this insufficient validation. Therefore, an orchestrator implementing the documented workflow could navigate its browser to an attacker-selected host. Redirects also require validation. Even if the initial hostname is restricted, an approved URL could redirect the browser to a loopback, link-local, private-network, or unrelated public destination unless every navigation target is checked. ### Attack Path 1. An attacker supplies a URL such as `http://127.0.0.1:8080/offer/1.html`. 2. `extractOfferId()` finds `/offer/1.html` and returns `1`. 3. The caller treats the URL as a valid ...[truncated 1323 chars]- Remediation
View remediation
