T09 · Insecure Skill Coding Practices
- Location
scripts/utils.py:49- Finding
Unvalidated Bilibili URLs Enable Arbitrary Network Requests and Automatic Browser-Cookie Use
- Content
View full analysis
str: """Detect video platform from URL.""" if "bilibili.com" in url or "b23.tv" in url: return "bilibili" elif "youtube.com" in url or "youtu.be" in url: return "youtube" return "unknown" ``` ```python if "b23.tv" in url: try: import requests r = requests.head(url, allow_redirects=True, timeout=10) url = r.url except Exception: pass ``` ```python base_cmd = [ "yt-dlp", "--no-check-certificates", "--retries", retries, "--fragment-retries", frag_retries, "-f", "bestvideo[height<=720]+bestaudio/best[height<=720]", "--merge-output-format", "mp4", "-o", video_path, url, ] try: subprocess.run(base_cmd, check=True, timeout=yt_dlp_timeout, capture_output=True) except subprocess.CalledProcessError: progress(" ⚠️ Retrying with browser cookies...") cookie_cmd = [ "yt-dlp", "--cookies-from-browser", "chrome", "--no-check-certificates", "--retries", retries, "--fragment-retries", frag_retries, "-f", "bestvideo[height<=720]+bestaudio/best[height<=720]", "--merge-output-format", "mp4", "-o", video_path, url, ] subprocess.run(cookie_cmd, check=True, timeout=yt_dlp_timeout, capture_output=True) ``` ### Technical Analysis Platform detection is based on substring matching against the entire URL rather than parsing and validating the hostname. An attacker can therefore supply a URL whose query, path, user-information component, or attacker-controlled hostname merely contains `bilibili.com` or `b23.tv`. The URL is then passed unchanged to `yt-dlp`. When `b ...[truncated 2217 chars]- Remediation
View remediation
