T09 · Insecure Skill Coding Practices
- Location
references/assets.md:180- Finding
Arbitrary HTTPS Asset Retrieval Enables SSRF and Unintended Data Exfiltration
- Content
View full analysis
{ // 1. Validate and download the file const url = new URL(sourceUrl); if (url.protocol !== "https:") { throw new Error("Only HTTPS URLs are supported"); } const sourceResponse = await fetch(sourceUrl); const buffer = Buffer.from(await sourceResponse.arrayBuffer()); // 2. Upload directly to HeyGen const response = await fetch("https://upload.heygen.com/v1/asset", { method: "POST", headers: { "X-Api-Key": process.env.HEYGEN_API_KEY!, "Content-Type": contentType, }, body: buffer, }); const json: AssetUploadResponse = await response.json(); if (json.code !== 100) { throw new Error(json.message ?? "Upload failed"); } return json.data; } ``` ### Technical Analysis The function accepts an externally supplied `sourceUrl` and validates only that its parsed scheme is HTTPS. This validation does not prevent requests to: - Loopback addresses such as `127.0.0.1` or `::1` - RFC 1918 private networks - Link-local and cloud metadata addresses - Internal services exposed through private DNS - Public URLs that redirect to internal destinations - DNS names that resolve differently between validation and connection After retrieving the target, the function buffers the entire response in memory and uploads it to HeyGen. Consequently, this is not only an SSRF primitive but also a potential data-exfiltration path from an internal service to an external third party. The implementation also has no response-size limit, download timeout, content validation, or redirect policy. A large or indefinitely streaming response could therefore cause excessive memory consumption or t ...[truncated 1155 chars]- Remediation
View remediation
