T09 · Insecure Skill Coding Practices
- Location
scripts/ush_report.py:38- Finding
PushPlus credential and report summary transmitted over plaintext HTTP
- Content
View full analysis
Vulnerability Details
File Location:
scripts/ush_report.py, lines 38-46
Vulnerability Type: Plaintext transmission of sensitive data
Risk Level: HighVulnerable Code:
python url = 'http://www.pushplus.plus/send' data = { "token": token, "title": title, "content": summary, "template": "txt" } try: response = requests.post(url, json=data, timeout=10)Technical Analysis
The script submits the
WECHAT_PUSH_KEY, report title, and report summary to PushPlus through an unencrypted HTTP connection. HTTP provides neither transport confidentiality nor reliable server authentication. Any attacker capable of observing or modifying traffic between the host and the remote service can inspect the request body or tamper with it.The exposed token may function as a reusable authorization credential for sending notifications through the associated PushPlus account. The report title and summary may also contain confidential business, financial, or research information.
Attack Path
- A user invokes the skill to push a report through the WeChat channel.
- The script reads
WECHAT_PUSH_KEYfrom the environment and places it in the JSON request body. - The script sends the request to
http://www.pushplus.plus/send. - An attacker with a suitable network position, such as a compromised gateway, hostile access point, or upstream network observer, intercepts the plaintext request.
- The attacker extracts the PushPlus token and report data or modifies the notification in transit.
- If the token remains valid and reusable, the attacker can use it to submit unauthorized notifications.
Impact Assessment
Successful exploitation can disclose the PushPlus authorization token, report title, and report summary. An attacker may be able to send unauthorized or misleading notifications to the token owner. This issue does not directly expose the QQ Mail authorization code ...[truncated 103 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the endpoint with
https://www.pushplus.plus/send. - Keep TLS certificate verification enabled and do not use
verify=False. - Explicitly reject redirects from HTTPS to HTTP before transmitting credentials.
- Consider restricting redirects entirely unless required by the documented API.
- Rotate the existing
WECHAT_PUSH_KEYbecause it may already have traversed untrusted networks in plaintext. - Avoid including secrets in exception messages, logs, or diagnostic output.
- Add an automated test that verifies all credential-bearing endpoints use HTTPS.
- Replace the endpoint with
