T09 · Insecure Skill Coding Practices
- Location
scripts/get_video_content.py:76- Finding
Server-Side Request Forgery Through Weak Short-Link Validation
- Content
View full analysis
- Remediation
View remediation
None: parsed = urlsplit(url) if parsed.scheme != "https": raise ValueError("Only HTTPS URLs are allowed") hostname = (parsed.hostname or "").lower().rstrip(".") if hostname not in ALLOWED_SHORT_LINK_HOSTS: raise ValueError("Unapproved short-link hostname") for result in socket.getaddrinfo(hostname, 443, type=socket.SOCK_STREAM): address = ipaddress.ip_address(result[4][0]) if not address.is_global: raise ValueError("Non-public destination address") validate_public_bilibili_url(url) response = self.session.head( url, allow_redirects=False, timeout=10, ) ``` If redirects are necessary, process them manually and apply equivalent validation to each `Location` destination before issuing the next request. ]]>
