T09 · Insecure Skill Coding Practices
- Location
scripts/ip_query_v6.py:21- Finding
API Key Exfiltration Through an Unrestricted API Base URL Override
- Content
View full analysis
Vulnerability Details
File Location:
scripts/ip_query_v6.py:21, 108-110
Vulnerability Type: Unrestricted destination control for credential-bearing requests
Risk Level: MediumVulnerable Code
python API_BASE_URL = os.environ.get("JIKE_API_BASE_URL", "https://api.jikeapi.cn").rstrip("/")python url = f"{API_BASE_URL}{API_PATH}?{urllib.parse.urlencode({'ip': ip_value, 'appkey': appkey})}" try: with urllib.request.urlopen(url, timeout=15) as response: return json.loads(response.read().decode("utf-8"))Technical Analysis
The undocumented
JIKE_API_BASE_URLenvironment variable controls the complete request origin and scheme. The script does not require HTTPS and does not verify that the destination hostname is the intendedapi.jikeapi.cnservice.The application key is appended to the request URL as an
appkeyquery parameter. Consequently, anyone capable of manipulating the process environment can redirect the request—and its credential—to an arbitrary HTTP or HTTPS endpoint. Query-string credentials may also be retained in web-server, reverse-proxy, monitoring, or network-device logs.Exploitation requires control over the environment in which the skill is launched, such as a compromised wrapper, launcher configuration, deployment manifest, shell profile, or parent process.
Attack Path
- An attacker gains the ability to modify the skill's launch environment or configuration.
- The attacker sets
JIKE_API_BASE_URLto an endpoint under their control, for examplehttp://attacker.example. - A user invokes the documented IPv6 lookup command.
- The script loads the user's API key from
--key,JIKE_IP_QUERY_V6_KEY,JIKE_APPKEY, or the local.envfile. - The script constructs a request to the attacker-controlled origin with the IPv6 address and API key in the query string.
- The attacker's server receives and records the API key.
- The attacker can reuse the stolen key against the legiti ...[truncated 618 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the
JIKE_API_BASE_URLoverride if alternate endpoints are not a required feature. - If configurability is necessary, parse the configured URL and enforce:
- The
httpsscheme. - An explicit hostname allowlist, preferably only
api.jikeapi.cn. - An approved port, path prefix, and absence of embedded user information.
- The
- Construct the endpoint from a fixed trusted origin rather than concatenating an unrestricted string.
- Send the API key in a supported authorization header instead of the query string. If the upstream API only accepts a query parameter, ensure URLs are redacted from application, proxy, and server logs.
- Document any supported endpoint override and treat control over it as security-sensitive.
- Add tests confirming that HTTP URLs, unapproved hosts, embedded credentials, and malformed destinations are rejected before any request containing the key is sent.
- Remove the
