T09 · Insecure Skill Coding Practices
- Location
scripts/xhs-core.js:47- Finding
Chromium Sandbox Disabled for Untrusted Web Content
- Content
View full analysis
Vulnerability Details
File Location:
scripts/xhs-core.js, lines 47-61
Vulnerability Type: Browser sandbox protection disabled
Risk Level: Highjavascript async function launchBrowser(headless = true) { const opts = { headless, args: ['--no-sandbox', '--disable-blink-features=AutomationControlled'], }; // Use a persistent user data directory to retain login state const userDataDir = path.join(DATA_DIR, 'browser-profile'); const context = await chromium.launchPersistentContext(userDataDir, { ...opts, viewport: { width: 1280, height: 800 }, userAgent: 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36', locale: 'zh-CN', }); return context; }Technical Analysis
The
--no-sandboxcommand-line argument explicitly disables Chromium's process sandbox for every browser operation performed by the skill. The browser loads live, externally controlled content from Xiaohongshu and can also navigate to a caller-provided URL through the detail command.Chromium's sandbox is a defense-in-depth boundary intended to contain renderer compromise. Disabling it does not independently create arbitrary code execution, but it significantly increases the consequences of a browser-engine vulnerability because compromised renderer code may no longer be contained by the normal browser sandbox.
The persistent browser context further contains authenticated session state, increasing the value of a successful browser compromise.
Attack Path
- An attacker publishes or injects content that exercises a vulnerability in the installed Chromium version.
- The skill navigates the browser to the affected content while processing a search, note detail, or other browser-driven operation.
- The attacker exploits the browser renderer vulnerability.
- Because Chromium was started with
--no-sandbox, the norma ...[truncated 645 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the
--no-sandboxargument and retain Chromium's default sandbox protections. - Run the skill as a standard, unprivileged operating-system user.
- Keep Playwright and its bundled Chromium version patched and reproducibly pinned.
- Isolate browser automation in a dedicated low-privilege account, container, or virtual machine when feasible.
- Restrict browser navigation to approved HTTPS Xiaohongshu hosts.
- Avoid exposing sensitive host directories to the browser process.
- Remove the
