T09 · Insecure Skill Coding Practices
- Location
scripts/fetch_and_send.py:24- Finding
TLS Certificate and Hostname Verification Disabled
- Content
View full analysis
Vulnerability Details
File Location:
scripts/fetch_and_send.py:24-27, with the unsafe context used at lines 145 and 268
Vulnerability Type: Improper TLS certificate validation
Risk Level: HighVulnerable Code
python ssl_context = ssl.create_default_context() ssl_context.check_hostname = False ssl_context.verify_mode = ssl.CERT_NONEThe unsafe context is subsequently used for both RSS retrieval and webhook delivery:
python with urllib.request.urlopen(req, timeout=15, context=ssl_context) as response: content = response.read().decode('utf-8', errors='ignore') return parse_rss(content, limit)python with urllib.request.urlopen(req, timeout=30, context=ssl_context) as response: result = json.loads(response.read().decode('utf-8'))Technical Analysis
Setting
check_hostnametoFalseandverify_modetossl.CERT_NONEdisables both certificate-chain verification and hostname validation. The client will therefore accept a certificate presented by any server, including a self-signed or attacker-controlled certificate.The same insecure TLS context is used for two security-sensitive operations:
- Retrieving news titles and links from external RSS providers.
- Sending the generated card to the configured Feishu webhook.
The Feishu webhook URL contains a secret token that authorizes message delivery. Because the complete URL is transmitted as part of the HTTPS request, a network attacker who successfully intercepts the connection can recover this credential. The flaw is unnecessary for the declared functionality because Python's default TLS context already supports secure HTTPS communication.
Attack Path
- An attacker obtains a network interception position, such as through a compromised router, malicious proxy, hostile wireless network, or DNS manipulation.
- The attacker redirects an RSS or Feishu connection to an attacker-controlled T ...[truncated 1251 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the custom context that disables certificate validation:
python ssl_context = ssl.create_default_context() - Do not modify
check_hostnameorverify_mode; retain their secure defaults. - Prefer omitting the
contextargument entirely so thaturllibuses the platform's trusted certificate store:python with urllib.request.urlopen(req, timeout=15) as response: ... - Apply the same correction to the Feishu webhook request:
python with urllib.request.urlopen(req, timeout=30) as response: ... - Fail closed when certificate verification fails. Do not retry using an insecure context.
- Avoid logging the complete webhook URL or token. The current output exposes only the final path component, but even that component may be sensitive and should be redacted.
- Rotate the Feishu webhook credential if the script has previously operated over an untrusted network with TLS verification disabled.
- Optionally restrict webhook destinations to an allowlisted HTTPS hostname such as
open.feishu.cnbefore transmitting the payload.
- Remove the custom context that disables certificate validation:
