T03 · Remote Payload Retrieval and Execution
- Location
scripts/ensure_env.py:28- Finding
Remote Python bootstrap is downloaded and executed without TLS verification
- Content
View full analysis
Vulnerability Details
File Location:
scripts/ensure_env.py:28, 279-295
Vulnerability Type: Unverified remote payload retrieval and execution
Risk Level: HighVulnerable code:
python ssl._create_default_https_context = ssl._create_unverified_contextpython get_pip_path = os.path.join(tempfile.gettempdir(), "get-pip.py") urls = [ "https://mirrors.huaweicloud.com/repository/pypi/simple/get-pip.py", "https://bootstrap.pypa.io/get-pip.py", ] ctx = ssl._create_unverified_context() for url in urls: info(f"尝试下载 get-pip.py: {url}") try: urllib.request.urlretrieve(url, get_pip_path, context=ctx) except Exception as e: print(f" 下载失败: {e}") continue rc, out, err = run_cmd([sys.executable, get_pip_path], timeout=120) if rc == 0: ok("get-pip.py 安装 pip 成功") return TrueTechnical Analysis
The mandatory environment-preparation flow invokes
_ensure_pip()whenpipis unavailable. If the localensurepipbootstrap also fails, the function downloadsget-pip.pyfrom an external URL and executes it with the current Python interpreter.Both the process-wide HTTPS context and the download-specific context disable certificate validation. The downloaded file is not authenticated using a pinned cryptographic hash or digital signature before execution. Consequently, HTTPS no longer establishes the identity of the remote server.
This behavior crosses a network-to-code-execution trust boundary: bytes supplied over an unauthenticated network channel become executable Python code. The Skill requires Huawei Cloud credentials to be present in environment variables before this setup flow succeeds, so injected code would execute in a process environment containing
HW_ACCESS_KEY,HW_SECRET_KEY, and potentiallyHW_SECURITY_TOKEN.Attack Path
- The user invokes the Skill, whose documented prerequisite ...[truncated 1357 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the process-wide assignment to
ssl._create_default_https_context. - Use Python’s default verified HTTPS context for all downloads.
- Do not create or pass
ssl._create_unverified_context()tourlretrieve. - Verify the downloaded bootstrap using a pinned SHA-256 digest or a trusted digital signature before execution.
- Download to a securely created, uniquely named temporary file and delete it after verification and execution.
- Prefer failing closed with manual installation instructions when
ensurepipis unavailable rather than automatically executing remote bootstrap code. - Run dependency setup before cloud credentials are placed in the process environment, reducing credential exposure if bootstrap execution is compromised.
- Remove the process-wide assignment to
