T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:31- Finding
Unrestricted Internal-Network URL Retrieval Enables SSRF
- Content
View full analysis
/data exec: curl -fsSL "" -o /data/table.csv ``` The surrounding instruction explicitly permits any downloadable URL, including localhost and internal-network URLs, and requires using `curl` rather than a restricted fetch facility. ### Technical Analysis The Skill directs the Agent to pass a user-controlled URL to `curl` without validating the destination. No controls restrict: - URL schemes - Loopback, private, or link-local addresses - Cloud metadata endpoints - DNS rebinding - Redirect destinations - Internal hostnames or ports - Response content type Although downloading a user-provided CSV or Excel file is part of the declared functionality, access to localhost and internal-network resources exceeds the minimum privileges needed. A public data-analysis Skill should not be able to retrieve arbitrary intranet or metadata resources. The `-L` option follows redirects, so validating only the initial URL would also be insufficient. ### Attack Path 1. An attacker asks the Agent to analyze a URL that resolves to an internal service, such as a loopback address, private-network host, or cloud metadata endpoint. 2. Following the Skill instructions, the Agent executes `curl -fsSL` with that URL. 3. The internal response is saved as a local file. 4. If the response can be parsed as tabular data, the analysis pipeline profiles and summarizes its content. 5. Generated JSON and reports may reveal internal data to the attacker. A public URL that redirects to an internal address could provide an equivalent path because redirects are followed. ### Impact Assessment Successful exploitation can provide read access to HTTP resources reachable from the Agent host but not from the attacker. Dependin ...[truncated 385 chars]- Remediation
View remediation
