T09 · Insecure Skill Coding Practices
- Location
snippets/common-configs.md:37- Finding
Gateway Listens on All Network Interfaces by Default
- Content
View full analysis
Vulnerability Details
File Location:
snippets/common-configs.md, lines 37–45
Vulnerability Type: Unsafe network exposure
Risk Level: MediumVulnerable Code
json { "gateway": { "host": "0.0.0.0", "port": 8080 } }Technical Analysis
The reusable gateway configuration binds the service to
0.0.0.0, causing it to listen on every available IPv4 network interface. The example does not include authentication, TLS, firewall restrictions, network allowlisting, or a warning about the security implications of exposing the gateway.Because this is presented as a ready-to-use common configuration, users may copy it into environments where port 8080 is reachable from a local network, container network, cloud network, or the public Internet. Actual exploitability depends on the gateway's authentication controls and surrounding network policy, neither of which is established by the audited project.
Attack Path
- A user copies the provided gateway configuration.
- The gateway starts and listens on port 8080 across all IPv4 interfaces.
- A firewall, container port mapping, cloud security group, or local network configuration permits another host to reach that port.
- An attacker discovers the exposed gateway through network scanning or prior knowledge.
- The attacker connects to any gateway functionality not protected by effective authentication and authorization controls.
Impact Assessment
If the deployed gateway lacks adequate compensating controls, an attacker within network reach could access exposed interfaces, APIs, operational information, or Agent-related functionality. The exact privileges and scope depend on the gateway implementation and its runtime authentication configuration. The audited snippet alone does not demonstrate privileged access or successful authentication bypass.
- Remediation
View remediation
Remediation Suggestions
- Change the default bind address to
127.0.0.1so the gateway is accessible only from the local host. - Require users to opt in explicitly before binding to
0.0.0.0. - Add a prominent warning explaining that
0.0.0.0exposes the service on all available IPv4 interfaces. - If remote access is necessary, require strong authentication and authorization for every gateway endpoint.
- Terminate TLS directly at the gateway or through a securely configured reverse proxy.
- Restrict inbound access with host firewalls, cloud security groups, container network policies, or IP allowlists.
- Avoid publishing port 8080 to public interfaces unless operationally required.
- Document a hardened remote-access example rather than presenting unrestricted binding as the common default.
- Add deployment checks that warn or fail when a gateway binds publicly without authentication or transport encryption.
- Change the default bind address to
