T09 · Insecure Skill Coding Practices
- Location
scripts/brickeconomy_cli.py:49- Finding
API Key Disclosure Through an Unrestricted API Base URL
- Content
View full analysis
Any: query = urllib.parse.urlencode(clean_params(params or {}), doseq=True) url = f"{self.base_url}{path}" if query: url = f"{url}?{query}" headers = {"Accept": "application/json", "x-apikey": self.api_key} return self._request("GET", url, headers) def _request(self, method: str, url: str, headers: dict[str, str]) -> Any: request = urllib.request.Request(url, headers=headers, method=method) try: with urllib.request.urlopen(request, timeout=self.timeout) as response: raw = response.read().decode("utf-8") ``` The destination is exposed as a command-line or environment-controlled value: ```python parser.add_argument( "--base-url", default=os.getenv("BRICKECONOMY_BASE_URL", DEFAULT_BASE_URL), help="BrickEconomy API base URL", ) ``` ```python def client_from_args(args: argparse.Namespace) -> BrickEconomyClient: return BrickEconomyClient(require_api_key(), args.base_url, args.timeout) ``` ### Technical Analysis The CLI permits `--base-url` and `BRICKECONOMY_BASE_URL` to specify an arbitrary URL. It does not validate the URL scheme, hostname, port, or path before attaching the real `BRICKECONOMY_API_KEY` as the `x-apikey` header. Consequently, the credential is not restricted to the documented BrickEconomy endpoint, `https://www.brickeconomy. ...[truncated 2041 chars]- Remediation
View remediation
