T03 · Remote Payload Retrieval and Execution
- Location
scripts/ensure_env.py:278- Finding
Remote Python Installer Downloaded and Executed Without TLS Verification
- Content
View full analysis
Vulnerability Details
File Location:
scripts/ensure_env.py, lines 28 and 278–294
Vulnerability Type: Unauthenticated remote payload retrieval and execution
Risk Level: HighVulnerable Code
python ssl._create_default_https_context = ssl._create_unverified_contextpython get_pip_path = os.path.join(tempfile.gettempdir(), "get-pip.py") urls = [ "https://mirrors.huaweicloud.com/repository/pypi/simple/get-pip.py", "https://bootstrap.pypa.io/get-pip.py", ] ctx = ssl._create_unverified_context() for url in urls: info(f"尝试下载 get-pip.py: {url}") try: urllib.request.urlretrieve(url, get_pip_path, context=ctx) except Exception as e: print(f" 下载失败: {e}") continue rc, out, err = run_cmd([sys.executable, get_pip_path], timeout=120)Technical Analysis
The environment bootstrap explicitly replaces Python's default HTTPS context with an unverified context. If
pipis unavailable andensurepipalso fails, the script downloadsget-pip.pythrough that unverified TLS connection and immediately executes it with the current Python interpreter.No certificate validation, pinned hash, or digital-signature verification is performed before execution. HTTPS therefore provides no reliable server authentication on this path. The downloaded file is mutable remote code whose content is not constrained by the audited package.
This path is reachable through the Skill's mandatory environment preparation workflow described in
SKILL.md. It is not merely an unused helper, although exploitation specifically requires the local environment to lack a workingpipand forensurepipto fail.Attack Path
- A user invokes the Skill and follows its mandatory environment-check workflow.
scripts/check_env.shorscripts/check_env.ps1launchesscripts/ensure_env.py.- The environment lacks a usable
pip, and the attemptedensurepip --upgradeoperation fails. _ensure_pip()downlo ...[truncated 1251 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the global override:
python ssl._create_default_https_context = ssl._create_unverified_context - Do not create or pass
ssl._create_unverified_context()tourlretrieve. - Use the platform's validated default TLS context:
python ctx = ssl.create_default_context() - Verify the downloaded installer against a securely pinned SHA-256 digest or trusted digital signature before execution.
- Download to a securely created temporary file rather than a fixed
get-pip.pypathname in the shared temporary directory. - Prefer terminating with manual installation instructions when
ensurepipis unavailable instead of automatically executing remotely fetched bootstrap code. - Keep trusted hashes versioned in the Skill package and update them only through a reviewed release process.
- Remove the global override:
