T03 · Remote Payload Retrieval and Execution
- Location
scripts/ensure_env.py:278- Finding
Remote Python bootstrap downloaded over unverified TLS and executed
- Content
View full analysis
Vulnerability Details
File Location:
scripts/ensure_env.py, lines 28 and 278–294
Vulnerability Type: Unverified remote payload retrieval and execution
Risk Level: HighVulnerable Code
python ssl._create_default_https_context = ssl._create_unverified_contextpython get_pip_path = os.path.join(tempfile.gettempdir(), "get-pip.py") urls = [ "https://mirrors.huaweicloud.com/repository/pypi/simple/get-pip.py", "https://bootstrap.pypa.io/get-pip.py", ] ctx = ssl._create_unverified_context() for url in urls: info(f"尝试下载 get-pip.py: {url}") try: urllib.request.urlretrieve(url, get_pip_path, context=ctx) except Exception as e: print(f" 下载失败: {e}") continue rc, out, err = run_cmd([sys.executable, get_pip_path], timeout=120)Technical Analysis
The mandatory environment setup attempts to install
pipwhen neither an existingpipinstallation norensurepipis available. As a fallback, it downloadsget-pip.pyfrom an external URL and immediately executes the downloaded file with the active Python interpreter.Both the process-wide HTTPS context and the explicit download context disable certificate verification. Consequently, HTTPS does not authenticate the remote server. No signature or pinned cryptographic digest is checked before execution.
The downloaded response is therefore attacker-influenced when a network-positioned adversary, compromised proxy, or other party capable of intercepting the connection is present. This crosses the trust boundary from untrusted network content to local executable code.
The Skill documentation requires users to run the environment check before executing queries. The vulnerable fallback is reached when:
- The environment check is invoked.
python -m pip --versionfails.python -m ensurepip --upgradealso fails.- One of the configured download URLs is reachable through an attacker-controlled network path.
Attack Path
...[truncated 1458 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the global TLS-verification override:
python ssl._create_default_https_context = ssl._create_unverified_context - Do not create or pass an unverified SSL context to
urlretrieve. - Use Python's default certificate-verifying TLS context:
python ctx = ssl.create_default_context() urllib.request.urlretrieve(url, get_pip_path, context=ctx) - Verify the downloaded bootstrap using a pinned cryptographic digest or trusted signature before execution.
- Prefer a single canonical HTTPS source rather than automatically executing content from multiple fallback sources.
- If secure bootstrap verification cannot be completed, fail safely and provide manual installation instructions instead of executing the file.
- Create the temporary file securely, restrict its permissions, and remove it after use.
- Consider eliminating remote bootstrap execution entirely and requiring
piporensurepipto be provisioned through the operating system's trusted package mechanism.
- Remove the global TLS-verification override:
