T09 · Insecure Skill Coding Practices
- Location
scripts/weibo_hot_search.py:93- Finding
Unrestricted URL Navigation Enables Server-Side Request Forgery
- Content
View full analysis
2: url = sys.argv[2] ``` ### Technical Analysis The application accepts a caller-controlled URL and passes it directly to Selenium's `driver.get()` method. It does not validate: - The URL scheme - The destination hostname - The destination port - Embedded credentials - DNS resolution results - Loopback, private, link-local, or metadata-service addresses - Redirect destinations Although the documented purpose is limited to scraping `s.weibo.com`, the implementation allows the browser to navigate to arbitrary network and local resources. This creates an SSRF primitive from the environment where the skill runs. A reachable attacker-controlled or internal page can reproduce the selectors expected by the scraper, such as elements under `#pl_top_realtimehot`, causing selected page content to be returned in the scraper's result. Non-HTTP schemes supported by the browser, including local-resource schemes, are also not explicitly rejected. ### Attack Path 1. An attacker or untrusted caller supplies a crafted value through `--url` or calls `get_weibo_hot_search()` with an arbitrary URL. 2. The URL targets a loopback service, private network service, cloud metadata endpoint, local resource, or attacker-controlled page. 3. Selenium navigates to the target from the skill host's network context. 4. The target receives a request that may ...[truncated 1010 chars]- Remediation
View remediation
