T09 · Insecure Skill Coding Practices
- Location
scripts/assess_vitality.py:103- Finding
Unrestricted API Endpoint and Unsafe URL Construction Enable SSRF
- Content
View full analysis
Vulnerability Details
File Location:
scripts/assess_vitality.py, lines 103-106 and 159-162
Vulnerability Type: Server-Side Request Forgery (SSRF) and unsafe URL construction
Risk Level: MediumVulnerable Code
python for coin in coins: url = f"{api_base}/api/metrics/{coin}?days={days}" try: metrics = await _fetch_json(url)python parser.add_argument( "--api", default=DEFAULT_API_BASE, help=f"Base URL of the Majestify API (default: {DEFAULT_API_BASE})" )Technical Analysis
The command-line
--apivalue is used as the request destination without validating its scheme, hostname, resolved IP address, or port. Consequently, a caller able to influence the script arguments can direct HTTP requests to loopback addresses, private networks, link-local services, or cloud metadata endpoints.The
coinvalue is also interpolated directly into the URL path without encoding or validation. Crafted values containing traversal sequences, query delimiters, or fragments may alter the intended/api/metrics/{coin}request path after processing by the client, proxy, or destination server.The script also permits plaintext HTTP endpoints. An attacker with a suitable network position could tamper with metric responses and influence the resulting financial classification. Response data is trusted with only a minimal check for the
sharpeRatiofield; the remaining schema and numeric ranges are not validated.Attack Path
- An attacker causes an agent or user to invoke the skill with an attacker-selected
--apiargument. - The attacker supplies a destination such as a loopback, private-network, link-local, or other internal HTTP service.
- If needed, the attacker supplies a crafted
--coinsvalue containing path manipulation characters to change the effective internal resource path. - The script constructs the URL directly from these values and
_fetch_jsonsends the request from the agent's n ...[truncated 979 chars]
- An attacker causes an agent or user to invoke the skill with an attacker-selected
- Remediation
View remediation
Remediation Suggestions
- Restrict API destinations to HTTPS and an explicit allowlist of trusted hostnames, using the documented Majestify endpoint as the default allowed destination.
- If custom endpoints are required, place them behind an explicit trusted configuration rather than accepting unrestricted runtime input.
- Parse URLs with
urllib.parse.urlsplitand reject embedded credentials, fragments, unexpected ports, and unsupported schemes. - Resolve destination hostnames and reject loopback, private, link-local, multicast, unspecified, reserved, and cloud-metadata address ranges for both IPv4 and IPv6.
- Revalidate the destination after every redirect, or disable redirects entirely. This is necessary to mitigate redirects and DNS-rebinding techniques that bypass an initial hostname check.
- Enforce a strict asset identifier pattern such as
^[a-z0-9-]+$and URL-encode the accepted value before inserting it into the path. - Validate
daysagainst a reasonable positive range to prevent malformed or abusive requests. - Validate the complete response schema, require finite numeric values, and enforce plausible metric ranges before classification.
- Avoid plaintext HTTP so that metric responses cannot be modified in transit.
