T09 · Insecure Skill Coding Practices
- Location
scripts/main.py:78- Finding
Configurable OCR Endpoint Can Exfiltrate API Credentials and Sensitive Documents
- Content
View full analysis
Vulnerability Details
File Location:
scripts/main.py:78-112
Vulnerability Type: Unrestricted destination for sensitive network transmission
Risk Level: HighVulnerable Code
python config.setdefault('SCNET_API_BASE', 'https://api.scnet.cn/api/llm/v1') return configpython api_base = config['SCNET_API_BASE'] api_key = config['SCNET_API_KEY'] url = f"{api_base}/ocr/recognize" if not os.path.isfile(file_path): sys.exit(f"File does not exist: {file_path}") mime_type, _ = mimetypes.guess_type(file_path) if mime_type is None: mime_type = 'application/octet-stream' headers = { 'Authorization': f'Bearer {api_key}' } try: with open(file_path, 'rb') as f: files = { 'file': (os.path.basename(file_path), f, mime_type) } data = { 'ocrType': ocr_type, 'channelTag': "scnetSkills" } response = requests.post( url, headers=headers, data=data, files=files, timeout=60 ) except Exception as e: sys.exit(f"Network request failed: {str(e)}")Technical Analysis
The destination of the OCR request is derived directly from the configurable
SCNET_API_BASEvalue. The implementation does not validate the URL scheme, destination hostname, port, or resulting request path before attaching the bearer credential and uploading the selected document.Although uploading the document to SCNet is necessary for the declared cloud OCR functionality, permitting an arbitrary destination is not required. Anyone able to modify
config/.envcan redirect the request to an attacker-controlled HTTP or HTTPS server. The request then discloses both:- The
SCNET_API_KEYbearer credential in theAuthorizationheader. - The complete user-selected education document in the multipart request body.
Education filing ...[truncated 1754 chars]
- The
- Remediation
View remediation
Remediation Suggestions
- Remove
SCNET_API_BASEconfigurability if only the official SCNet service is supported. - If endpoint configuration is operationally required, parse the URL and enforce:
- The
httpsscheme. - An explicit allowlist of trusted hostnames, preferably only
api.scnet.cn. - The expected port and API path.
- No embedded user information or ambiguous URL components.
- The
- Disable automatic redirects with
allow_redirects=False, or independently validate every redirect destination before resending credentials or file content. - Refuse loopback, link-local, private-network, and non-HTTPS destinations unless a separately documented enterprise mode explicitly requires them.
- Display a clear disclosure and obtain user authorization before uploading documents containing personal information.
- Protect
config/.envwith restrictive permissions and verify that it is owned by the expected user before loading sensitive configuration. - Use narrowly scoped, revocable API tokens and rotate a token immediately if endpoint tampering is suspected.
- Remove
