T09 · Insecure Skill Coding Practices
- Location
scripts/character_query.py:25- Finding
Unvalidated API Endpoint Override Can Disclose the AppKey
- Content
View full analysis
Vulnerability Details
File Location:
scripts/character_query.py:25andscripts/character_query.py:147
Vulnerability Type: Unvalidated destination override and credential disclosure
Risk Level: MediumVulnerable code:
python API_BASE_URL = os.environ.get("JIKE_API_BASE_URL", "https://api.jikeapi.cn").rstrip("/")python url = f"{API_BASE_URL}{API_PATH_MAP[command]}?{urllib.parse.urlencode({**params, 'appkey': appkey})}"Technical Analysis
The undocumented
JIKE_API_BASE_URLenvironment variable completely controls the origin to which API requests are sent. The application does not validate the URL scheme, hostname, port, or resolved destination before appending the API path and transmitting the request.The request URL includes the AppKey as a query parameter. Consequently, anyone able to influence the process environment can redirect a legitimate invocation to an attacker-controlled endpoint and receive both the AppKey and the submitted dictionary query. Allowing arbitrary destinations can also cause requests to be issued to internal network services or loopback addresses, creating a limited server-side request forgery condition in the runtime's network context.
Exploitation requires the attacker to control or poison the environment used to launch the skill. This finding does not establish that such control is available to an unauthenticated remote attacker.
Attack Path
- An attacker gains the ability to define environment variables for the process that runs the skill, such as through a compromised launcher, deployment configuration, wrapper script, or inherited shell environment.
- The attacker sets
JIKE_API_BASE_URLto an endpoint under their control, for examplehttps://attacker.example. - A user invokes any documented dictionary query while a legitimate AppKey is configured.
load_appkey()retrieves the legitimate credential from the command line, environme ...[truncated 1032 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the
JIKE_API_BASE_URLoverride from production builds and use the fixed trusted endpointhttps://api.jikeapi.cn. - If endpoint customization is required for testing, require an explicit development-mode option and reject it in production.
- Parse customized URLs and enforce all of the following:
- The scheme must be
https. - The hostname must exactly match an approved allowlist.
- User information and URL fragments must be absent.
- Ports must be restricted to approved values.
- Loopback, link-local, private, and otherwise sensitive network destinations must be rejected where arbitrary hosts are supported.
- The scheme must be
- Construct URLs with validated URL components rather than concatenating an untrusted base string.
- If supported by the service, transmit the AppKey in an authorization header instead of the query string to reduce exposure through URL logs, proxies, and monitoring systems.
- Document all supported configuration variables and ensure launchers sanitize inherited environment variables.
- Add tests confirming that HTTP URLs, unapproved hosts, loopback addresses, embedded credentials, and malformed endpoint values are rejected before any request is sent.
- Remove the
