T05 · Unauthorized Access and Privilege Escalation
- Location
automation-script.js:32- Finding
Unrestricted Target URL Permits Internal Network Access
- Content
View full analysis
!arg.startsWith('--')); const mobile = args.includes('--mobile'); const outputArg = args.find(arg => arg.startsWith('--output=')); const outputDir = outputArg ? outputArg.split('=')[1] : './results'; if (!url) { console.error('❌ Error: URL is required'); process.exit(1); } try { // Run audit const results = await runLighthouseAudit(url, { mobile }); ``` ### Technical Analysis The command-line target is passed directly to Lighthouse without validating its URL scheme, hostname, resolved IP address, or redirect destinations. There are no restrictions preventing access to: - Loopback addresses such as `127.0.0.1` or `::1` - RFC 1918 private networks - Link-local addresses - Internal D ...[truncated 2217 chars]- Remediation
View remediation
