T09 · Insecure Skill Coding Practices
- Location
scripts/caipiao_lottery_query.py:168- Finding
Unvalidated API Endpoint Override Can Disclose the AppKey
- Content
View full analysis
Vulnerability Details
File Location:
scripts/caipiao_lottery_query.py:25andscripts/caipiao_lottery_query.py:168-170
Vulnerability Type: Arbitrary API endpoint override and credential disclosure
Risk Level: MediumVulnerable Code
python API_BASE_URL = os.environ.get("JIKE_API_BASE_URL", "https://api.jikeapi.cn").rstrip("/")python url = f"{API_BASE_URL}{API_PATH_MAP[command]}?{urllib.parse.urlencode({**params, 'appkey': appkey})}" try: with urllib.request.urlopen(url, timeout=15) as response:Technical Analysis
The undocumented
JIKE_API_BASE_URLenvironment variable can replace the trusted API origin with an arbitrary URL. The application does not validate the URL scheme, hostname, port, or destination before appending the user's AppKey and issuing the request.Because the AppKey is included in the URL query string, a process launcher, wrapper, compromised execution environment, or other actor capable of controlling environment variables can redirect the request to an attacker-controlled server. The resulting request transmits the legitimate credential outside the intended
api.jikeapi.cntrust boundary.This behavior exceeds the documented purpose of communicating with the Jike API and creates a credential-exfiltration path. Placing the credential in the query string also increases its potential exposure through server access logs, proxy logs, and diagnostic tooling.
Attack Path
- The victim configures a valid AppKey through
JIKE_CAIPIAO_LOTTERY_QUERY_KEY,JIKE_APPKEY, the command line, orscripts/.env. - An attacker or compromised launcher sets
JIKE_API_BASE_URLto an attacker-controlled endpoint, such ashttps://attacker.example. - The victim invokes any documented command, such as
latestordetail. load_appkey()retrieves the victim's legitimate AppKey.request_api()constructs a URL under the attacker-controlled origin and ad ...[truncated 736 chars]
- The victim configures a valid AppKey through
- Remediation
View remediation
Remediation Suggestions
-
Remove the
JIKE_API_BASE_URLoverride from production code and use a fixed trusted endpoint:python API_BASE_URL = "https://api.jikeapi.cn" -
If endpoint substitution is required for development or testing, make it an explicit development-only feature and enforce:
- An exact allowlist of approved hostnames.
- HTTPS as the only permitted scheme.
- Rejection of embedded credentials, fragments, unexpected ports, and non-public or local destinations.
- A separate test credential that cannot access production resources.
-
Validate the parsed endpoint before every request. Do not rely on string-prefix checks; use
urllib.parse.urlparse()and compare the normalized scheme and hostname against an allowlist. -
Prefer sending the credential in an authorization header if supported by the service rather than in the query string. This reduces exposure through URL logs and diagnostic output.
-
Ensure redirects cannot forward credentials to an untrusted origin. Disable redirects or verify the destination origin before following them when sensitive credentials are attached.
-
Add automated tests confirming that HTTP URLs, unapproved domains, loopback addresses, private-network destinations, and malformed endpoints are rejected before any credential-bearing request is sent.
-
