T03 · Remote Payload Retrieval and Execution
- Location
scripts/ensure_env.py:278- Finding
Unauthenticated Remote Python Payload Download and Execution
- Content
View full analysis
Vulnerability Details
File Location:
scripts/ensure_env.py, lines 28 and 278–291
Vulnerability Type: Remote payload retrieval and execution without TLS authentication
Risk Level: HighVulnerable Code
python ssl._create_default_https_context = ssl._create_unverified_contextpython get_pip_path = os.path.join(tempfile.gettempdir(), "get-pip.py") urls = [ "https://mirrors.huaweicloud.com/repository/pypi/simple/get-pip.py", "https://bootstrap.pypa.io/get-pip.py", ] ctx = ssl._create_unverified_context() for url in urls: info(f"Attempting to download get-pip.py: {url}") try: urllib.request.urlretrieve(url, get_pip_path, context=ctx) except Exception as e: print(f"Download failed: {e}") continue rc, out, err = run_cmd([sys.executable, get_pip_path], timeout=120)Technical Analysis
The mandatory environment bootstrap falls back to downloading
get-pip.pywhen neither pip norensurepipis available. It explicitly creates an unverified TLS context and globally replaces Python's default HTTPS context with an unverified context.The downloaded file is not authenticated through a valid server certificate, cryptographic digest, or digital signature. It is then immediately executed by the current Python interpreter. Consequently, the HTTPS URL does not establish an authenticated code origin.
This path is reachable when:
- The Skill's required environment check is invoked.
- pip is unavailable.
ensurepip --upgradefails.- One of the configured download URLs is reachable through an attacker-controlled or intercepted network path.
Attack Path
- The user or Agent invokes the environment check required by
SKILL.md. _ensure_pip()determines that pip is unavailable and thatensurepipcannot install it.- A network attacker intercepts the request to a configured
get-pip.pyendpoint. - Because certificate verification is disabled, the attacker supplies an a ...[truncated 1006 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the global override:
python ssl._create_default_https_context = ssl._create_unverified_context - Do not use
ssl._create_unverified_context()for executable downloads. Use the default verified TLS context. - Prefer failing safely and instructing the user to install pip through a trusted operating-system package manager.
- If downloading a bootstrap script remains necessary:
- Use a canonical authenticated source.
- Pin an expected SHA-256 digest distributed independently of the downloaded file.
- Verify the digest before execution.
- Prefer a signed artifact and validate its signature against a pinned public key.
- Create temporary files securely and remove the downloaded script after successful or failed verification.
- Abort execution on any certificate, hostname, digest, or signature validation failure.
- Remove the global override:
