T09 · Insecure Skill Coding Practices
- Location
scripts/douyin_download.py:4- Finding
Unrestricted URL Retrieval and Arbitrary File Overwrite
- Content
View full analysis
{output_path}') return output_path if __name__ == '__main__': url = sys.argv[1] output = sys.argv[2] if len(sys.argv) > 2 else r'C:\Users\39535\.openclaw\workspace\tmp\douyin.mp4' download(url, output) ``` The same unsafe, unbounded download pattern is also presented as reusable code in `references/download.md`, lines 24-43. ### Technical Analysis The script accepts both `video_url` and `output_path` directly from command-line arguments. Neither value is validated before use. The URL is passed to `urllib.request.urlopen` without restricting its scheme, hostname, resolved IP address, port, or redirect destination. Consequently, the downloader is not limited to Douyin resources despite its intended purpose. Depending on supported URL handlers and runtime configuration, it may access arbitrary HTTP or HTTPS endpoints, internal network services, loopback services, or local resources through schemes such as `file:`. Redirects are followed without validating the final destination. Therefore, validating only an initial Douyin-looking URL outside this function would not be sufficient: an allowed endpoint could redirect the request to a private or otherwise prohibited destination. The output p ...[truncated 2493 chars]- Remediation
View remediation
