T09 · Insecure Skill Coding Practices
- Location
references/server-launcher.md:68- Finding
Python Backend Exposed on All Network Interfaces with Permissive CORS
- Content
View full analysis
1 else 8800 uvicorn.run(app, host="0.0.0.0", port=port) ``` ### Technical Analysis The recommended backend pattern binds Uvicorn to `0.0.0.0`, causing the service to listen on every available network interface rather than only the loopback interface. This contradicts the localhost-only security model declared in `SKILL.md` and `SECURITY.md`. The example also enables wildcard origins, methods, and headers through CORS. Consequently, any origin accepted by the browser's network security model can interact with these endpoints. Independent of CORS, another device on the same reachable network can directly send requests to the exposed port. The template does not add authentication or authorization. Workflows that copy this canonical example and later introduce file processing, model management, command execution, or sensitive-data endpoints may expose those operations without access control. ### Attack Path 1. A user follows the documented ServerLauncher backend example. 2. The workflow starts Uvicorn on `0.0.0.0:8800`, or another configured port. 3. The operating system firewall permits access from a local or otherwise connected network. 4. An attacker discovers the service through port scanning, service enumeration, or knowledge of the documented default ports. 5. The attacker calls unauthenticated workflow endpoints directly. 6. If those endpoints process local files, manage models, or pe ...[truncated 1010 chars]- Remediation
View remediation
