T09 · Insecure Skill Coding Practices
- Location
scripts/main.py:78- Finding
Unrestricted API destination may disclose credentials and uploaded documents
- Content
View full analysis
Vulnerability Details
File Location:
scripts/main.py:78-112
Vulnerability Type: Unvalidated outbound network destination
Risk Level: Mediumpython config.setdefault('SCNET_API_BASE', 'https://api.scnet.cn/api/llm/v1') def recognize_with_retry(ocr_type, file_path, config, retry_count=0): api_base = config['SCNET_API_BASE'] api_key = config['SCNET_API_KEY'] url = f"{api_base}/ocr/recognize" mime_type, _ = mimetypes.guess_type(file_path) if mime_type is None: mime_type = 'application/octet-stream' headers = { 'Authorization': f'Bearer {api_key}' } try: with open(file_path, 'rb') as f: files = { 'file': (os.path.basename(file_path), f, mime_type) } data = { 'ocrType': ocr_type, 'channelTag': "scnetSkills" } response = requests.post( url, headers=headers, data=data, files=files, timeout=60 )Technical Analysis
The optional
SCNET_API_BASEsetting is used directly to construct the request URL without validating its scheme, hostname, port, or trust relationship. The request carries both the Scnet bearer credential and the complete contents of the selected document.Although sending a document to the default Scnet endpoint is necessary for the declared remote OCR functionality, allowing an unrestricted destination exceeds the minimum network privileges required for that functionality. A modified or incorrectly supplied configuration can redirect requests to an unrelated host. The code also does not require HTTPS, so a configured HTTP endpoint would expose the credential and document to interception.
Attack Path
- An attacker, compromised deployment mechanism, or unsafe configuration process alters `conf ...[truncated 1098 chars]
- Remediation
View remediation
Remediation Suggestions
- Use a fixed, allowlisted Scnet HTTPS origin for production credentials.
- Parse the endpoint with a standard URL parser and require the
httpsscheme. - Validate the normalized hostname against an explicit allowlist such as
api.scnet.cn. - Reject URLs containing embedded user information, fragments, unexpected ports, or ambiguous hostnames.
- Do not send a production Scnet credential to a custom endpoint.
- If custom endpoints are a required advanced feature, use a separate endpoint-specific credential and require explicit user confirmation before transmitting a document.
- Log the normalized destination before transmission without logging the API key or document contents.
- Add tests covering HTTP URLs, lookalike domains, embedded credentials, malformed URLs, and attacker-controlled hosts.
