T09 · Insecure Skill Coding Practices
- Location
lib/gen_qweather_token.js:58- Finding
Live QWeather Bearer JWT Exposed Through Standard Output
- Content
View full analysis
Vulnerability Details
File Location:
lib/gen_qweather_token.js:58-63
Vulnerability Type: Sensitive credential exposure through logging
Risk Level: MediumVulnerable Code
js const { token, payload } = generateJwtEd25519(CONFIG.PROJECT_ID, CONFIG.CREDENTIALS_ID, CONFIG.PRIVATE_KEY_PATH); console.log("JWT TOKEN:"); console.log(token); console.log("\nPayload preview:"); console.log(payload);Technical Analysis
The token-generation utility writes the complete signed QWeather JWT to standard output. This JWT is used as a bearer credential and can therefore be replayed by anyone who obtains it while it remains valid.
Standard output is commonly captured by CI systems, process supervisors, terminal recording software, container logs, and centralized logging platforms. Consequently, printing the token unnecessarily expands access to an authentication credential beyond the process that generated it.
The generated token has an approximately 15-minute lifetime. The checked-in project currently contains placeholder identifiers and a malformed sample private-key file, so successful exploitation requires an operator first to configure valid QWeather credentials. Once configured, however, running this utility produces the disclosure directly.
Attack Path
- An operator replaces the placeholder QWeather configuration and key material with valid credentials.
- The operator runs
lib/gen_qweather_token.jsto test JWT generation. - The process prints the complete signed bearer JWT to standard output.
- A CI service, terminal recorder, process supervisor, or centralized logging system retains the output.
- An unauthorized party with access to those logs extracts the JWT.
- The party replays the token against the configured QWeather API before its expiration.
Impact Assessment
An attacker who obtains the logged token can temporarily exercise the QWeather API permissions associa ...[truncated 398 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
console.log(token)and never print complete bearer credentials by default. - Display only non-sensitive metadata, such as the expiration time, subject, and a one-way token fingerprint.
- If raw token output is operationally unavoidable, require an explicit command-line option and display a prominent warning before emitting it.
- Ensure CI and production logging configurations redact JWT-shaped values and
Authorizationheaders. - Restrict access to process and build logs and configure short retention periods.
- Document that generated JWTs are sensitive credentials and must not be copied into tickets, chat messages, or persistent logs.
- Remove
