T09 · Insecure Skill Coding Practices
- Location
scripts/taobao_research.js:174- Finding
Unrestricted Product Image Fetching Enables Blind SSRF and Resource Exhaustion
- Content
View full analysis
{ const protocol = url.startsWith('https') ? https : http; const file = fs.createWriteStream(filepath); protocol.get(url, (response) => { if (response.statusCode !== 200) { reject(new Error(`Failed to download: ${response.statusCode}`)); return; } response.pipe(file); file.on('finish', () => { file.close(); resolve(filepath); }); }).on('error', reject); }); } ``` ```javascript // scripts/taobao_research.js:249-256 const p = products[i]; if (p.image) { try { const ext = p.image.match(/\.(jpg|jpeg|png|gif)/i)?.[0] || '.jpg'; const imgPath = path.join(imageDir, `img_${i+1}${ext}`); await this.downloadImage(p.image, imgPath); p.localImage = imgPath; ``` ### Technical Analysis The image URL is extracted from marketplace-controlled page content and passed directly to Node.js `http.get` or `https.get`. The implementation does not parse and validate the URL, restrict destination hostnames, resolve and reject private or loopback addresses, impose request timeouts, limit response size, or verify that the response is an authentic supported image. The protocol decision only checks whether the string starts with `https`; all other nonempty values are handed to the HTTP client. A malicious or compromised product listing could th ...[truncated 2326 chars]- Remediation
View remediation
