T09 · Insecure Skill Coding Practices
- Location
tradejournal.py:101- Finding
Bearer API Credential Can Be Redirected to an Untrusted Host
- Content
View full analysis
Dict: """Make authenticated request to Simmer API.""" if not SIMMER_API_KEY: raise ValueError("SIMMER_API_KEY environment variable not set") url = f"{SIMMER_API_URL}{endpoint}" if params: # Filter None values and URL-encode parameters filtered = {k: v for k, v in params.items() if v is not None} url = f"{url}?{urlencode(filtered)}" headers = { "Authorization": f"Bearer {SIMMER_API_KEY}", "Content-Type": "application/json", } req = Request(url, headers=headers, method=method) try: with urlopen(req, timeout=REQUEST_TIMEOUT_SECONDS) as response: ``` ### Technical Analysis The complete API origin is read from the undocumented `SIMMER_API_URL` environment variable. The program then attaches the `SIMMER_API_KEY` bearer credential to requests sent to that origin. No validation restricts the destination to `https://api.simmer.markets`, verifies that HTTPS is used, or prevents credentials from being sent to an unrelated hostname. Consequently, any party capable of influencing the process environment can redirect authenticated synchronization requests to a server under its control. Using an environment variable for an endpoint can be legitimate in development, but forwarding a production bearer credential to an unrestricted origin violates least-privilege and credential-boundary principles. The documented functionality only requires authenticated communication with the official Simmer API. ### Attack Path 1. An attacker gains the a ...[truncated 1402 chars]- Remediation
View remediation
