T09 · Insecure Skill Coding Practices
- Location
scripts/kie-callback-server.py:8- Finding
Unauthenticated Public Callback Endpoint Permits Arbitrary Data Persistence
- Content
View full analysis
- Remediation
View remediation
` and return `404` or `403` for all other POST paths. 4. Enforce a conservative maximum body size before calling `read`, such as 256 KB, and reject missing, invalid, negative, or excessive `Content-Length` values with HTTP `413`. 5. Require the expected JSON content type and validate the parsed callback against a strict schema. 6. Do not persist all incoming headers. Explicitly retain only non-sensitive fields required for troubleshooting. 7. Use collision-resistant filenames containing a task ID plus a random UUID, and create files atomically with exclusive creation semantics. 8. Configure file permissions so only the service account can read callback data. 9. Add expiration and storage quotas for callback records. 10. Place rate limiting and request-size controls in front of the tunnel. 11. Replace the single-threaded server or configure strict read timeouts to mitigate slow-request denial of service. ]]>
