T05 · Unauthorized Access and Privilege Escalation
- Location
references/query-templates.md:53- Finding
Unrestricted User-Controlled Endpoint Access Enables SSRF
- Content
View full analysis
{ SELECT ?s (COUNT(?s) AS ?count) ?o WHERE { GRAPH <{G}> { ?s a ?o . } } GROUP BY ?s ?o ORDER BY DESC(?count) LIMIT 50 } } ``` ``` The execution-routing instructions also explicitly prioritize direct requests: ```text Default execution order for query execution: 1. Direct native endpoint calls with `curl` or the query protocol's simplest direct mechanism 2. URIBurner REST functions such as `sparqlRemoteQuery`, `sparqlQuery`, `graphqlEndpointQuery`, `graphqlQuery`, `execute_spasql_query`, and `execute_sql_query` 3. MCP via `https://linkeddata.uriburner.com/chat/mcp/messages` or `https://linkeddata.uriburner.com/chat/mcp/sse` 4. Authenticated LLM-mediated execution via `https://linkeddata.uriburner.com/chat/functions/chatPromptComplete` 5. OPAL Agent routing using recognizable OPAL function names ``` ### Technical Analysis The `{E}` placeholder is derived from an endpoint URL supplied in the user's prompt and is inserted into a SPARQL `SERVICE` clause without an endpoint allowlist, URI-scheme restriction, DNS/IP validation, or redirect policy. The instructions also permit direct native requests using `curl`. Consequently, an attacker can cause either the local Agent environment or a remote SPARQL processor to initiate a connection to an attacker-selected destination. Depending on the selected route and network topology, targets could include loopback addresses, private-network services, link-local resou ...[truncated 1739 chars]- Remediation
View remediation
