T09 · Insecure Skill Coding Practices
- Location
scripts/generate.sh:19- Finding
Unrestricted URL Fetching Enables Server-Side Request Forgery in Post Generation
- Content
View full analysis
Vulnerability Details
File Location:
scripts/generate.sh:19-24
Vulnerability Type: Server-Side Request Forgery (SSRF)
Risk Level: MediumVulnerable Code:
bash if echo "$input" | grep -qE '^https?://'; then echo "Fetching article: $input" >&2 content=$(curl --silent --max-time 20 -L \ -H "User-Agent: Mozilla/5.0" \ "$input" 2>&1)Technical Analysis
The script treats any string beginning with
http://orhttps://as an article URL and passes it directly tocurl. It does not validate the hostname, resolved IP address, destination port, or URL redirect chain.The
-Loption follows redirects automatically. Consequently, validating only the original URL scheme is insufficient: an attacker can provide either a direct internal URL or a public URL that redirects to a loopback, link-local, private-network, or cloud metadata address.Retrieving public article content is required by the declared functionality. However, allowing arbitrary access to network locations unavailable to the caller exceeds the minimum network privileges required by the Skill.
The code does not collect credentials or transmit environment variables. The security issue is unrestricted destination access rather than deliberate sensitive-data exfiltration.
Attack Path
- An attacker supplies a URL such as an internal service address, cloud metadata endpoint, or attacker-controlled public URL.
- The Agent invokes
scripts/generate.shwith that URL. curl -Lsends the request from the Agent host and follows any redirects without validating their destinations.- The request can reach services on loopback, private networks, or link-local networks that are inaccessible to the external attacker.
- The response is stored in
contentand parsed for its title, description, and body. - Parsed title or description data may be included in generated output, while other response characteristics can ...[truncated 665 chars]
- Remediation
View remediation
Remediation Suggestions
- Permit only the
httpsscheme unless plain HTTP is explicitly required. - Parse URLs with a dedicated URL parser rather than relying only on a regular-expression prefix check.
- Resolve the destination hostname before connecting and reject IPv4 and IPv6 addresses in loopback, private, link-local, multicast, unspecified, documentation, and reserved ranges.
- Restrict destination ports to an explicit allowlist, preferably ports 80 and 443.
- Disable redirects where possible. If redirects are necessary, resolve and validate every redirect destination before following it.
- Protect against DNS rebinding by ensuring the validated address is the address used for the connection.
- Run article retrieval in a sandbox with egress rules that block internal networks and cloud metadata endpoints.
- Apply response-size limits in addition to the existing time limit.
- Return a clear error when destination validation fails, without exposing internal connection details.
- Permit only the
