T05 · Unauthorized Access and Privilege Escalation
- Location
server/services/report_service.py:29- Finding
Unauthenticated Agent Token Replacement Enables Account Takeover
- Content
View full analysis
Agent: """ 注册新 Agent 或更新已有 Agent """ token_hash = hashlib.sha256(token.encode("utf-8")).hexdigest() agent = Agent.query.filter_by(agent_id=agent_id).first() if agent: # 更新 agent.token_hash = token_hash agent.updated_at = datetime.utcnow() else: # 新建 agent = Agent( agent_id=agent_id, token_hash=token_hash, ) db.session.add(agent) for key in ("name", "os_info", "python_version", "monitor_version", "total_skills", "runnable_skills"): if key in kwargs and kwargs[key] is not None: setattr(agent, key, kwargs[key]) db.session.commit() return agent ``` ### Technical Analysis The registration endpoint is unauthenticated and treats registration of an existing `agent_id` as an update. When the identifier a ...[truncated 1549 chars]- Remediation
View remediation
