T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/serve_reports.py:411- Finding
Unauthenticated report server listens on all network interfaces
- Content
View full analysis
"${LOG_FILE}" 2>&1 & SERVER_PID=$! echo "${SERVER_PID}" > "${PID_FILE}" ``` ### Technical Analysis Passing an empty host string to `HTTPServer` binds the service to all available network interfaces rather than only the loopback interface. The server implements no authentication or authorization before serving directory listings and report files. This conflicts with the loopback URLs displayed by `scripts/manage_server.sh`, which may lead users to believe that the service is locally accessible only. Because the Skill workflow directs the Agent to start the report service after report generation, the exposure can occur without a user explicitly requesting a network-wide service. Reports stored in `~/.stock-invest-master` can contain company research, watchlists, investment decisions, valuation assumptions, and other user-specific information. ### Attack Path 1. A user invokes the Skill and generates an investment report. 2. The automated workflow starts `serve_reports.py` through `manage_server.sh`. 3. `HTTPServer(("", port), ReportServer)` listens on every host interface, normally on port 8888. 4. An attacker with network access to the host connects to `http://HOST:8888/`. 5. The attacker browses the unauthenticated directory listing. 6. The attacker requests and downloads available Markdown, HTML, JSON, CSV, text, or image reports. ### Impact Assessme ...[truncated 421 chars]- Remediation
View remediation
