T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/fetch_wechat.js:61- Finding
Unrestricted Browser Navigation Enables Server-Side Request Forgery
- Content
View full analysis
a.startsWith('http')); ``` ```js await page.goto(url, { waitUntil: 'networkidle', timeout: 30000 }); ``` From `scripts/screenshot_wechat.js`: ```js const args = process.argv.slice(2); const url = args.find(a => a.startsWith('http')); ``` ```js await page.goto(url, { waitUntil: 'load', timeout: 30000 }); ``` ### Technical Analysis The scripts accept any argument beginning with `http` and pass it directly to Playwright. They do not enforce the Skill's declared `mp.weixin.qq.com` scope, require HTTPS, reject embedded credentials or unusual ports, constrain redirects, or block loopback, private, link-local, and cloud metadata addresses. Consequently, Chrome can make requests using the execution host's network access rather than the requesting user's access. Browser navigation also follows redirects, so validating only the initial URL would remain insufficient. ### Attack Path 1. An attacker supplies a URL such as an internal HTTP service or an attacker-controlled URL that redirects to one. 2. The prefix check accepts the URL because it begins with `http`. 3. Playwright navigates to the target from the Skill execution environment. 4. `fetch_wechat.js` extracts visible text, or `screenshot_wechat.js` captures the rendered response. 5. The resulting internal content is exposed through command output or the screenshot workflow. ### Impact Assessment An attacker may access HTTP resources reachable from the execution environment, including localhost services, private-network administration interfaces, and potentially cloud metadata endpoints. The practical scope depends on the host's network placement ...[truncated 218 chars]- Remediation
View remediation
