T05 · Unauthorized Access and Privilege Escalation
- Location
src/server-v15.js:332- Finding
Authentication Bypass Exposes Chat History, Live Streams, and AI Execution
- Content
View full analysis
{ const sessionId = req.params.sessionId; const history = chatHistory[sessionId] || []; res.json(history.slice(-200)); }); app.get('/api/session/:sessionId', (req, res) => { const sessionId = req.params.sessionId; const sessionConfig = config.sessions[sessionId] || {}; res.json({ sessionId, model: sessionConfig.model || 'qwen3.5-plus', createdAt: sessionConfig.createdAt, updatedAt: sessionConfig.updatedAt }); }); app.post('/api/auth/check', (req, res) => { const { password } = req.body; if (!password) { return res.status(400).json({ authenticated: false, error: '需要密码' }); } const authenticated = password === authConfig.password; res.json({ authenticated }); }); app.get('/api/export/:sessionId', (req, res) => { const sessionId = req.params.sessionId; const format = req.query.format || 'json'; const history = chatHistory[sessionId] || []; // Returns the selected history without an authorization check. }); app.post('/api/chat', (req, res) => { const { message, sessionId = 'web-chat', model } = req.body; // ... streamAI( message, sessionId, sessionModel, // ... ); }); io.on('connection', (socket) => { socket.on('join', (sessionId) => { const roomId = sessionId || 'web-chat'; socket.join(roomId); const history = chatHistory[sessionId] || []; socket.emit('history', history.slice(-200)); }); }); server.listen(PORT, '0.0.0.0', () => { // ... }); ``` ### Technical Analysis The password-check endpoint only returns a Boolean. It does not create an authenticated server-side session, issue a token, set a secure cookie, or establish an authorization context. None of ...[truncated 1728 chars]- Remediation
View remediation
