T09 · Insecure Skill Coding Practices
- Location
fetch_article.py:85- Finding
WeChat Session Cookie Disclosure Through an Unrestricted Article URL
- Content
View full analysis
Tuple[Optional[str], Optional[str], Optional[int]]: headers = { "User-Agent": ( "Mozilla/5.0 (Windows NT 10.0; Win64; x64) " "AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36" ), "Accept": "text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8", "Accept-Language": "zh-CN,zh;q=0.9,en;q=0.8", "Referer": "https://mp.weixin.qq.com/", "Upgrade-Insecure-Requests": "1", } if cookie: headers["Cookie"] = cookie try: r = requests.get(url, headers=headers, timeout=timeout) except Exception as e: return None, "request_failed: %s" % e, None ``` ```python cookie = str(req.get("cookie") or os.environ.get("WECHAT_MP_COOKIE", "")).strip() ... else: page_html, err, status = _fetch(url, cookie) ``` ### Technical Analysis The requested URL is taken directly from the request body and passed to `requests.get()` without validating its scheme, hostname, port, resolved address, or redirect destination. Although the script is declared as a WeChat article fetcher, it does not restrict requests to `mp.weixin.qq.com`. If the request does not contain an explicit cookie, the script automatically loads the sensitive `WECHAT_MP_COOKIE` environment variable. `_fetch()` then adds this value to the `Cookie` header for any supplied URL. Consequently, an untrusted URL can receive the victim's complete WeChat session cookie. The lack of URL restrictions also creates a server-side request forgery primitive. The script can request localhost, private network services, link-local addresses, and other destinations reachable from the execution enviro ...[truncated 1324 chars]- Remediation
View remediation
