T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/export-native-pptx.py:1097- Finding
Unrestricted Remote and Local Image Retrieval During Native Export
- Content
View full analysis
bool: """ Forelements with http(s)/file sources and object-fit: cover: download the original image, PIL-crop to the exact visible pixel region, and embed the cropped image. Only handles cover — other fits fall back to Playwright screenshot so that CSS opacity and rendering are captured correctly. Returns True on success, False to fall back to screenshot. """ # Handle cover, contain, fill, and empty (default) — other values fall back to screenshot. if object_fit not in ('cover', 'contain', 'fill', ''): return False try: import urllib.request from PIL import Image as _PILImg import ssl if source.startswith('file://'): img_path = source[len('file://'):] with open(img_path, 'rb') as f: img_bytes = f.read() else: req = urllib.request.Request(source, headers={'User-Agent': 'Mozilla/5.0'}) try: import certifi _ssl_ctx = ssl.create_default_context(cafile=certifi.where()) except ImportError: _ssl_ctx = ssl._create_unverified_context() with urllib.request.urlopen(req, context=_ssl_ctx, timeout=15) as resp: img_bytes = resp.read() ``` The retrieval function is invoked for URLs extracted from HTML image elements: ```python def export_raster_element(page: Page, slide, elem: Dict[str, Any]): """Render DOM-backed raster elements (
, , url() backgrounds) as PPT pictures.""" export_id = elem.get('exportId') if not export_id: raise ValueError("Raster element ...[truncated 2834 chars]
- Remediation
View remediation
