T09 · Insecure Skill Coding Practices
- Location
scripts/marktplaats-place-probe.js:418- Finding
Arbitrary destination requests can forward cookies and attacker-controlled authentication headers
- Content
View full analysis
{ const idx = value.indexOf(':'); if (idx === -1) return [value, '']; return [value.slice(0, idx).trim(), value.slice(idx + 1).trim()]; })), }); const cookie = options.cookie ?? loadCookieFile(options.cookieFile); if (cookie) { headers.set('Cookie', cookie); } const response = await fetch(options.url, { redirect: 'follow', headers, }); const body = await response.text(); const isLoginRedirect = /\/identity\/v2\/login\b/.test(response.url) || /Inloggen op uw account/i.test(body); const security = detectSecuritySignals(body, response.url); const bodyLimit = Number.isFinite(options.bodyLimit) ? options.bodyLimit : 0; const bodyPreview = bodyLimit === 0 ? '' : body.slice(0, bodyLimit); return { source: 'curl', url: response.url, status: response.status, ok: response.ok, isLoginRedirect, security, requestHeaders: { 'user-agent': userAgent, accept: headers.get('Accept'), }, headers: Object.fromEntries(response.headers.entries()), body: bodyPreview, bodyTruncated: bodyPreview.length < body.length, bodyLen ...[truncated 2932 chars]- Remediation
View remediation
