T09 · Insecure Skill Coding Practices
- Location
skills/alphafold-skill/scripts/rest_request.py:63- Finding
Caller-Controlled URLs Enable Server-Side Request Forgery Across Generic REST Clients
- Content
View full analysis
str: if path.startswith(("http://", "https://")): return path ...[truncated 3258 chars]- Remediation
View remediation
str: if not isinstance(path, str) or not path.strip(): raise ValueError("A relative API path is required.") if urlsplit(path).scheme or urlsplit(path).netloc: raise ValueError("Absolute URLs are not permitted.") url = urljoin("https://alphafold.ebi.ac.uk/api/", path.lstrip("/")) parsed = urlsplit(url) port = parsed.port or 443 if (parsed.scheme, parsed.hostname, port) != ALLOWED_ORIGIN: raise ValueError("Destination origin is not allowed.") return url ``` ]]>
