T09 · Insecure Skill Coding Practices
- Location
assets/main_handler.js:10- Finding
Unrestricted URL Navigation Enables Server-Side Request Forgery
- Content
View full analysis
document.body.innerText); ``` ```js crawler.run([targetUrl]); ``` `assets/youtube_handler.js:3-4, 33, 90`: ```js const targetUrl = process.argv[2]; const videoId = targetUrl.split('v=')[1]?.split('&')[0]; ``` ```js await page.goto(targetUrl, { waitUntil: 'networkidle' }); ``` ```js crawler.run([targetUrl]); ``` ### Technical Analysis Both handlers accept a URL directly from a command-line argument and pass it to Crawlee and Playwright without validating its scheme, hostname, resolved IP address, or redirect destination. In `main_handler.js`, a URL is treated as generic unless its text contains `youtube.com`. Generic pages are opened and their title and visible body text are returned to stdout. Consequently, an attacker who can control the command-line URL can direct the browser toward HTTP services accessible from the container, including loopback interfaces, private network addresses, link-local services, and potentially cloud instance metadata endpoints. Validating only the original textual hostname would not be sufficient. A robust defense must account for DNS rebinding, IPv4 and IPv6 representations, redirects to prohibited destinations, and hostnames that resolve to private or reserved addresses. The browser is additionally launched with `--no-sandbox` and `--disable-setuid-sandbox` in `assets/main_handler.js:23` ...[truncated 2224 chars]- Remediation
View remediation
