T09 · Insecure Skill Coding Practices
- Location
scripts/send_image.sh:55- Finding
Unrestricted Remote Image Retrieval Enables SSRF and Internal Data Forwarding
- Content
View full analysis
&2 TEMP_FILE=$(mktemp /tmp/feishu_image.XXXXXX) curl -s -o "$TEMP_FILE" "$IMAGE_INPUT" if [[ ! -s "$TEMP_FILE" ]]; then echo "Error: Failed to download image from URL" >&2 rm -f "$TEMP_FILE" exit 1 fi IMAGE_FILE="$TEMP_FILE" echo "Image downloaded to: $IMAGE_FILE" >&2 else # Use local file IMAGE_FILE="$IMAGE_INPUT" if [[ ! -f "$IMAGE_FILE" ]]; then echo "Error: Image file not found: $IMAGE_FILE" >&2 exit 1 fi echo "Step 2: Using local image file" >&2 fi # Step 3: Upload image echo "Step 3: Uploading image to Feishu..." >&2 IMAGE_KEY=$("${SCRIPT_DIR}/upload_image.sh" -f "$IMAGE_FILE" -t "$TOKEN") echo "Image uploaded, key: $IMAGE_KEY" >&2 # Cleanup temp file if we downloaded one if [[ -n "${TEMP_FILE:-}" && -f "$TEMP_FILE" ]]; then rm -f "$TEMP_FILE" fi # Step 4: Send message echo "Step 4: Sending message..." >&2 MESSAGE_ID=$("${SCRIPT_DIR}/send_message.sh" -r "$RECEIVE_ID" -k "$IMAGE_KEY" -t "$TEXT" -a "$TOKEN") ``` ### Technical Analysis The script accepts an arbitrary HTTP or HTTPS URL through `IMAGE_INPUT` and passes it directly to `curl`. It does not validate the destination hostname or resolved IP address and does not reject loopback, link-local, private-network, or other reserved destinations. Consequently, the script can make network requests using the host's network position. The downloaded response is then uploaded to Feishu and delivered to a caller-selected recipient. This turns the functionality into a potential SSRF and data-forwarding primitive when an untrusted party can influence the script arguments. The download also lacks connection and transfer timeo ...[truncated 2060 chars]- Remediation
View remediation
