T09 · Insecure Skill Coding Practices
- Location
scripts/housing_bridge_server.py:196- Finding
Unauthenticated Localhost Bridge Exposes Authenticated Browser Content
- Content
View full analysis
controller.abort(), timeout_ms); try { const r = await fetch(url, { credentials: "include", redirect: "follow", signal: controller.signal }); const html = await r.text(); const finalUrl = r.url; const isLogin = looksLikeLoginPage(html, finalUrl); return { status: r.status, final_url: finalUrl, content_length: html.length, html: html, ``` ### Technical Analysis The bridge binds to localhost by default but does not authenticate requests to `/fetch`, `/poll`, `/result`, `/heartbeat`, or `/health`. It also returns `Access-Control-Allow-Origin: *`, allowing JavaScript from an arbitrary website to send requests to the local service and read its responses. A request to `/fetch` becomes a task for the Chrome extension ...[truncated 1765 chars]- Remediation
View remediation
