T09 · Insecure Skill Coding Practices
- Location
lib/torchsdk/tokens.js:354- Finding
Creator-Controlled Metadata URI Enables Server-Side Request Forgery
- Content
View full analysis
controller.abort(), 10000); const res = await fetch(uri, { signal: controller.signal }).finally(() => clearTimeout(timer)); const data = (await res.json()); metadata = { description: data.description, image: data.image, twitter: data.twitter, telegram: data.telegram, website: data.website, }; } catch (e) { warnings.push(`Metadata fetch failed: ${e instanceof Error ? e.message : String(e)}`); } } ``` ### Technical Analysis The value of `bondingCurve.uri` is controlled by the token creator and stored on-chain. When `getToken()` is called, the SDK passes this value directly to `fetch()`. The implementation does not validate: - The URL scheme - The destination hostname - The resolved IP address - Whether the destination is loopback, link-local, or part of a private network - Redirect destinations - The response content type - The maximum response size The ten-second `AbortController` timeout reduces the duration of a slow request but does not prevent server-side request forgery. Redirects are followed by default, meaning an initially acceptable endpoint could redirect the request to an internal address. In Node.js or another server-side runtime, this behavior allows an attacker to cause requests from the Agent's network environment. Browser same-origin restrictions may limit some deployments, but they do not protect server-side execution. ### Attack Path 1. An attacker creates a Torch token. ...[truncated 1395 chars]- Remediation
View remediation
