T09 · Insecure Skill Coding Practices
- Location
SKILL.md:32- Finding
TLS Certificate Verification Disabled for Authenticated Proxmox API Requests
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 32–285 and line 308
Vulnerability Type: TLS certificate validation bypass
Risk Level: HighVulnerable Code
The documented API commands consistently use
curl -k, including requests that transmit the Proxmox API token and perform privileged operations:bash curl -sk -H "$AUTH" "$PVE_URL/api2/json/cluster/status" | jq curl -sk -X POST -H "$AUTH" \ "$PVE_URL/api2/json/nodes/{node}/qemu/{vmid}/status/start" curl -sk -X DELETE -H "$AUTH" \ "$PVE_URL/api2/json/nodes/{node}/qemu/{vmid}?purge=1&destroy-unreferenced-disks=1"The practice is explicitly recommended at line 308:
markdown - Use `-k` for self-signed certsTechnical Analysis
The
-k/--insecureoption disables TLS certificate verification. Encryption may still occur, but the client no longer verifies that it is communicating with the legitimate Proxmox server.Every request includes the reusable API credential through the
Authorization: PVEAPIToken=$PVE_TOKENheader. An attacker capable of intercepting or redirecting network traffic can present an arbitrary certificate without causingcurlto reject the connection. This allows the attacker to capture the token, inspect API responses, or modify privileged requests and responses.Attack Path
- A user follows the documented commands against a Proxmox endpoint.
- An attacker gains a network interception position or redirects the configured endpoint through DNS, routing, or local network manipulation.
- The attacker presents an untrusted certificate.
- Because
curl -kdisables verification, the client accepts the certificate. - The authenticated request, including the
PVE_TOKENauthorization header, is sent to the attacker-controlled endpoint. - The attacker captures and reuses the token against the genuine Proxmox API.
- Subject to the token's permissions, the attacker can inspect in ...[truncated 603 chars]
- Remediation
View remediation
Remediation Suggestions
-
Remove
-kfrom every documentedcurlcommand. -
Install the Proxmox server certificate or issuing CA in the client's trusted certificate store.
-
For a private CA, use an explicit trusted CA file:
bash curl --fail-with-body --show-error --silent \ --cacert "/secure/path/proxmox-ca.pem" \ -H "$AUTH" \ "$PVE_URL/api2/json/cluster/status" -
Consider certificate or public-key pinning for high-value automation.
-
Validate that
PVE_URLuses HTTPS and points to an approved hostname. -
Rotate the API token if it has previously been used over connections where certificate verification was disabled.
-
Fail closed when TLS verification fails rather than offering
-kas the default workaround.
-
