T09 · Insecure Skill Coding Practices
- Location
autoecom.py:79- Finding
Unrestricted URL Fetching and Arbitrary File Write
- Content
View full analysis
Vulnerability Details
File Location:
autoecom.py:79-82andautoecom.py:172-178
Vulnerability Type: Server-Side Request Forgery and unrestricted file output
Risk Level: HighVulnerable Code
python def http_get(url: str, *, timeout: int = 30) -> requests.Response: res = requests.get(url, headers={"User-Agent": UA}, timeout=timeout) res.raise_for_status() return respython def cmd_download(args: argparse.Namespace) -> None: out = Path(args.out).resolve() out.parent.mkdir(parents=True, exist_ok=True) log(f"GET {args.url}") res = http_get(args.url, timeout=60) out.write_bytes(res.content) print(json.dumps({ "url": args.url, "path": str(out), "bytes": len(res.content), "content_type": res.headers.get("content-type"), }, indent=2))Related URL-fetching behavior also occurs when processing product pages and product images through
http_get.Technical Analysis
The download command accepts an unrestricted URL and an unrestricted destination path. The implementation does not:
- Restrict URLs to HTTP or HTTPS.
- Reject loopback, private, link-local, multicast, or reserved IP addresses.
- Revalidate the destination of HTTP redirects.
- Restrict downloads to expected storefront or CDN domains.
- Enforce response-size or image-type limits.
- Confine output to the project, state, or output directories.
This is particularly significant because the documented workflow derives logo and product-image URLs from remotely controlled storefront content. A malicious or compromised storefront could return image references targeting internal services, including loopback services, private network applications, or cloud instance metadata endpoints. The
requestslibrary follows redirects by default, so validating only the original URL would not be sufficient.The output path is resolved but not check ...[truncated 1863 chars]
- Remediation
View remediation
Remediation Suggestions
- Permit only
httpsand, where explicitly required,httpURLs. - Resolve hostnames before connecting and reject loopback, private, link-local, multicast, unspecified, and reserved IPv4 and IPv6 addresses.
- Disable automatic redirects or validate every redirect target with the same rules.
- Prefer an allowlist derived from the configured storefront domain and explicitly approved CDN domains.
- Stream responses with a strict byte limit rather than loading the entire body before validation.
- Require expected image MIME types and verify downloaded content with Pillow before saving it as an image.
- Restrict output paths to a designated directory:
- Resolve both the approved root and requested path.
- Verify the requested path is a descendant of the approved root.
- Reject symlink escapes and existing sensitive files.
- Run network-facing operations under a low-privilege account with restricted network egress.
- Apply the same URL validation to product-page requests and image URLs loaded from
plan.json.
- Permit only
