T09 · Insecure Skill Coding Practices
- Location
scripts/clawdraw.mjs:1913- Finding
DNS Rebinding Can Bypass Image URL SSRF Validation
- Content
View full analysis
= 16 && parts[1] <= 31) || (parts[0] === 192 && parts[1] === 168) || (parts[0] === 169 && parts[1] === 254) || parts[0] === 0 || address === '::1' || address.startsWith('fe80:') || address.startsWith('fc00:') || address.startsWith('fd'); if (isPrivate) { throw new Error('Private/internal URLs are not allowed.'); } } ``` The validated hostname is subsequently fetched using a separate DNS resolution: ```js res = await fetch(url, { redirect: 'manual', signal: controller.signal, }); // Handle redirects manually — re-validate target against SSRF rules if (res.status >= 300 && res.status < 400) { const location = res.headers.get('location'); if (!location) throw new Error('Redirect with no Location header'); const redirectUrl = new URL(location, url).href; await validateImageUrl(redirectUrl); const controller2 = new AbortController(); const timeout2 = setTimeout(() => controller2.abort(), 30_000); try { res = await fetch(redirectUrl, { redirec ...[truncated 2750 chars]- Remediation
View remediation
