T09 · Insecure Skill Coding Practices
- Location
scripts/petrol_query.py:21- Finding
Undocumented API Base URL Override Allows AppKey Disclosure
- Content
View full analysis
Vulnerability Details
File Location:
scripts/petrol_query.py, lines 21 and 143–147
Vulnerability Type: Credential disclosure through an unvalidated destination URL
Risk Level: MediumVulnerable Code
python API_BASE_URL = os.environ.get("JIKE_API_BASE_URL", "https://api.jikeapi.cn").rstrip("/")python params = {"appkey": appkey} if province: params["province"] = province url = f"{API_BASE_URL}{API_PATH}?{urllib.parse.urlencode(params)}" try: with urllib.request.urlopen(url, timeout=15) as response: return json.loads(response.read().decode("utf-8"))Technical Analysis
The script accepts an undocumented
JIKE_API_BASE_URLenvironment variable and uses its value as the destination for API requests without validating its scheme or hostname. The AppKey is then inserted into the query string and transmitted to that destination.Although the documented service endpoint is
https://api.jikeapi.cn, an execution environment can replace it with an arbitrary URL, including an attacker-controlled HTTP or HTTPS server. Consequently, a secret obtained independently from--key,JIKE_PETROL_QUERY_KEY,JIKE_APPKEY, orscripts/.envcan be sent outside the intended trust boundary.Placing the credential in the query string further increases exposure because URLs may be retained in web-server access logs, reverse-proxy logs, monitoring systems, and diagnostic records.
Attack Path
- An attacker controls or influences the environment used to launch the skill, while the legitimate AppKey remains available through another configured credential source.
- The attacker sets
JIKE_API_BASE_URLto an attacker-controlled endpoint, such ashttps://attacker.example. - A user or agent executes the documented petrol query command.
load_appkeyobtains the legitimate AppKey from the command line, environment, or local.envfile.request_apiconstructs a ...[truncated 870 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove the
JIKE_API_BASE_URLoverride in production and use a fixed trusted endpoint:python API_BASE_URL = "https://api.jikeapi.cn" -
If endpoint customization is required for testing, expose it only through an explicit development mode and validate the parsed URL:
- Require the
httpsscheme. - Require the hostname to match an allowlist.
- Reject embedded credentials, unexpected ports, fragments, and non-HTTPS destinations.
- Resolve and validate the final destination after redirects, or disable cross-origin redirects.
- Require the
-
Prefer transmitting the AppKey in an authorization header rather than the query string if the API supports it:
python request = urllib.request.Request(url) request.add_header("Authorization", f"Bearer {appkey}") -
Avoid logging complete request URLs or headers containing credentials.
-
Rotate any AppKey that may have been used while an untrusted
JIKE_API_BASE_URLvalue was present. -
Add tests confirming that HTTP endpoints, unknown hostnames, malformed URLs, and cross-origin redirects are rejected before any credential is transmitted.
-
