T09 · Insecure Skill Coding Practices
- Location
script/kuaidi100.js:29- Finding
Sensitive API credentials and personal logistics data exposed in URL query strings
- Content
View full analysis
Vulnerability Details
File Location:
script/kuaidi100.js, lines 29–107
Vulnerability Type: Sensitive information transmitted through URL query parameters (CWE-598)
Risk Level: MediumVulnerable Code
js function makeRequest(path, params) { return new Promise((resolve, reject) => { const queryStr = querystring.stringify(params); const fullPath = `${BASE_PATH}${path}?${queryStr}`; const options = { hostname: BASE_URL, path: fullPath, method: 'GET' }; const req = https.request(options, (res) => { let data = ''; res.on('data', (chunk) => { data += chunk; }); res.on('end', () => { resolve(data); }); }); req.on('error', (error) => { reject(error); }); req.end(); }); } async function queryTrace(kuaidiNum, phone = null) { const params = { key: getKey(), kuaidiNum: kuaidiNum }; if (phone) { params.phone = phone; } return await makeRequest('/queryTrace', params); } async function autoNumber(kuaidiNum) { const params = { key: getKey(), kuaidiNum: kuaidiNum }; return await makeRequest('/autoNumber', params); } async function estimatePrice(kuaidicom, recAddr, sendAddr, weight = '1') { const params = { key: getKey(), kuaidicom: kuaidicom, recAddr: recAddr, sendAddr: sendAddr, weight: weight }; return await makeRequest('/estimatePrice', params); } async function estimateTime(kuaidicom, from, to, orderTime = null, expType = null) { const params = { key: getKey(), kuaidicom: ...[truncated 2721 chars]- Remediation
View remediation
Remediation Suggestions
- Use HTTPS POST and place sensitive request parameters in the request body if the Kuaidi100 API supports POST requests.
- Send the API key in an authorization header rather than in the URL if the vendor provides a header-based authentication mechanism.
- If the API contract requires GET parameters, configure all proxies, gateways, application servers, monitoring products, and vendor integrations to redact or omit query strings from logs.
- Minimize the data sent to each endpoint and avoid transmitting phone numbers, addresses, or full logistics histories unless required for the requested operation.
- Inform users before transmitting personal shipment information to the third-party API and apply appropriate retention and privacy controls.
- Use narrowly scoped API credentials where supported, monitor their usage, enforce quota alerts, and rotate any key suspected of appearing in URL logs.
- Add automated tests or static-analysis rules that reject credentials and sensitive personal data placed in URL query parameters.
