T09 · Insecure Skill Coding Practices
- Location
SKILL.md:11- Finding
Plex authentication token exposed through plaintext transport and URL query parameters
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:11, 19, 24, 30, 35, 40, 45, 50, 55
Vulnerability Type: Credential exposure through insecure transport and query-string authentication
Risk Level: MediumVulnerable Code
bash # SKILL.md:11 - `PLEX_SERVER`: Your Plex server URL (e.g., `http://192.168.1.100:32400`) # SKILL.md:19 curl -s "$PLEX_SERVER/?X-Plex-Token=$PLEX_TOKEN" -H "Accept: application/json" # SKILL.md:24 curl -s "$PLEX_SERVER/library/sections?X-Plex-Token=$PLEX_TOKEN" -H "Accept: application/json" # SKILL.md:30 curl -s "$PLEX_SERVER/library/sections/1/all?X-Plex-Token=$PLEX_TOKEN" -H "Accept: application/json" # SKILL.md:35 curl -s "$PLEX_SERVER/search?query=SEARCH_TERM&X-Plex-Token=$PLEX_TOKEN" -H "Accept: application/json" # SKILL.md:40 curl -s "$PLEX_SERVER/library/recentlyAdded?X-Plex-Token=$PLEX_TOKEN" -H "Accept: application/json" # SKILL.md:45 curl -s "$PLEX_SERVER/library/onDeck?X-Plex-Token=$PLEX_TOKEN" -H "Accept: application/json" # SKILL.md:50 curl -s "$PLEX_SERVER/status/sessions?X-Plex-Token=$PLEX_TOKEN" -H "Accept: application/json" # SKILL.md:55 curl -s "$PLEX_SERVER/clients?X-Plex-Token=$PLEX_TOKEN" -H "Accept: application/json"Technical Analysis
The documented configuration explicitly permits an unencrypted
http://Plex server URL. Every documented API request also expands the sensitivePLEX_TOKENenvironment variable directly into the request URL as theX-Plex-Tokenquery parameter.If HTTP is used, the authentication token and returned Plex data are transmitted without transport encryption. An attacker with visibility into the local network, a compromised gateway, or a malicious proxy can inspect the request and recover the token. Such an attacker may also alter responses in transit.
Even when HTTPS is used, placing credentials in a query string increases their exposure. Complete URLs can be retained by Plex access logs, re ...[truncated 1630 chars]
- Remediation
View remediation
Remediation Suggestions
- Require
PLEX_SERVERto usehttps://and reject plaintext HTTP endpoints before making requests. - Keep TLS certificate verification enabled. Do not introduce
curl -kor--insecure. - Send the token through Plex's authentication header instead of the URL query string:
bash curl --fail-with-body --silent --show-error \ -H "Accept: application/json" \ -H "X-Plex-Token: $PLEX_TOKEN" \ "$PLEX_SERVER/library/sections" - Where local process-argument confidentiality is required, avoid placing the token directly in command-line arguments. Use a permission-restricted curl configuration or another secret-injection mechanism that does not expose the token in the process command line.
- Validate
PLEX_SERVERagainst an explicit set of trusted HTTPS hosts to reduce accidental token disclosure to an attacker-controlled endpoint. - Ensure reverse proxies and application logs do not record authentication headers or sensitive query parameters.
- Store
PLEX_TOKENonly in a protected secret store or environment with appropriately restricted access. Never print it in logs or diagnostic output. - Revoke and rotate any token that may previously have been transmitted over plaintext HTTP or retained in URL logs.
- Require
