T09 · Insecure Skill Coding Practices
- Location
scripts/delivery_notifier_debug.py:28- Finding
Debug Utility Exposes Complete Private Email Contents in Logs
- Content
View full analysis
1: print(f"Response part[1] type: {type(response_part[1])}") if response_part[1] is not None: msg = email.message_from_bytes(response_part[1]) subject_parts = decode_header(msg["Subject"]) subject = "".join([part.decode(encoding if encoding else 'utf-8', errors='replace') if isinstance(part, bytes) else str(part) for part, encoding in subject_parts]) from_ = str(msg.get("From")) body = msg.get_payload(decode=True).decode(errors='replace') results.append({"id": e_id.decode() if isinstance(e_id, bytes) else str(e_id), "from": from_, "subject": subject, "body": body}) ``` ```python notifications = fetch_delivery_notifications() print(json.dumps(notifications, indent=2)) ``` ### Technical Analysis The debug utility retrieves messages with the IMAP `RFC822` fetch attribute, which returns the complete email record. This can include message headers, sender and recipient addresses, message bodies, MIME structure, and attachment data. The script writes the raw IMAP response directly to standard output. It then parses the message, stores its full body in `results`, and serializes that result to standard output again. Consequently, sensitive mailbox information is disclosed twice. If the utility is executed under cron, CI, a service manager, a remote shell, or an environment with terminal recording or centralized log collection, complete email records may be retained out ...[truncated 1392 chars]- Remediation
View remediation
