T09 · Insecure Skill Coding Practices
- Location
scripts/douyin_downloader.py:72- Finding
Server-Side Request Forgery Through Unrestricted Share URL Fetching
- Content
View full analysis
Vulnerability Details
File Location:
scripts/douyin_downloader.py, lines 72–78
Vulnerability Type: Server-Side Request Forgery (SSRF)
Risk Level: HighVulnerable Code:
python urls = re.findall(r'http[s]?://(?:[a-zA-Z]|[0-9]|[$-_@.&+]|[!*\(\),]|(?:%[0-9a-fA-F][0-9a-fA-F]))+', share_text) if not urls: raise ValueError("未找到有效的分享链接") share_url = urls[0] share_response = requests.get(share_url, headers=HEADERS) share_response.raise_for_status() video_id = share_response.url.split("?")[0].strip("/").split("/")[-1]Technical Analysis
The downloader extracts the first HTTP or HTTPS URL from user-controlled input and sends a request to it without validating the destination. There is no hostname allowlist, port restriction, resolved-address check, or redirect validation. Because
requests.get()follows redirects by default, an initially public URL can also redirect the process to a loopback, private, link-local, or cloud metadata address.The Skill only needs to resolve legitimate Douyin links. Allowing requests to arbitrary hosts exceeds the minimum network privileges necessary for that functionality.
Attack Path
- An attacker supplies a crafted
--linkvalue containing a URL such ashttp://127.0.0.1:<port>/, a private-network endpoint, or an attacker-controlled redirector. parse_share_url()accepts the URL because it only checks its textual HTTP(S) format.- The process sends the request using its own network access.
- If redirects are involved,
requestsfollows them without validating each destination. - The attacker can trigger requests to services reachable from the execution environment and observe errors, timing, or externally visible side effects.
Impact Assessment
Successful exploitation can allow internal network probing, interaction with localhost or intranet services, and attempts to reach cloud instance metadata endpoints. Although th ...[truncated 280 chars]
- An attacker supplies a crafted
- Remediation
View remediation
Remediation Suggestions
- Accept only HTTPS URLs belonging to an explicit allowlist of required Douyin domains.
- Reject URLs containing embedded credentials, fragments, nonstandard ports, or malformed hostnames.
- Resolve the hostname before connecting and reject loopback, private, link-local, multicast, reserved, and unspecified IP ranges for both IPv4 and IPv6.
- Disable automatic redirects or validate the scheme, hostname, port, and resolved address of every redirect target.
- Apply connection and read timeouts.
- Prefer extracting a numeric video ID locally when the input already uses the documented stable share-link format.
- Add automated tests covering localhost, private addresses, IPv6 loopback, DNS rebinding scenarios, and public-to-private redirects.
