T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/pet_detection_feeder_analysis.py:228- Finding
Caller-Controlled Identity Enables Unauthorized Account Impersonation
- Content
View full analysis
Vulnerability Details
File Location:
scripts/pet_detection_feeder_analysis.py:228,245;skills/smyx_common/scripts/util.py:551-561,578-612
Vulnerability Type: Authentication bypass and account impersonation
Risk Level: HighVulnerable Code
python # scripts/pet_detection_feeder_analysis.py:228 parser.add_argument("--open-id", required=False, help=argparse.SUPPRESS) # scripts/pet_detection_feeder_analysis.py:245 OpenIdUtil.resolve_current_open_id( args.open_id, use_current=bool(args.open_id) )python # skills/smyx_common/scripts/util.py:551-561 _url = ApiEnum.BASE_URL_HEALTH + "/sys/phoneLogin" open_id = username _data = { "silent": 1, "register": 1, "openId": open_id, "mobile": username, "source": ConstantEnum.DEFAULT__SKILL_HUB_NAME } try: _response = requests.post(_url, json=_data) if _response.status_code == 200: _response_json = _response.json() if _response_json and _response_json.get("success"): return _response_json and _response_json.get("result")python # skills/smyx_common/scripts/util.py:578-612 current__user_name = ( ApiEnum.API_SECRET_KEY or ConstantEnum.CURRENT__USER_NAME or ConstantEnum.CURRENT__OPEN_ID ) found_user = None if (not ApiEnum.TOKEN or not ApiEnum.OPEN_TOKEN) and current__user_name: try: from .dao import UserDao, User user_dao = UserDao() found_user = user_dao.get_by_username(current__user_name) if found_user: ApiEnum.TOKEN = found_user.token ApiEnum.OPEN_TOKEN = found_user.open_token current__user_name = found_user.username if not ApiEnum.TOKEN or not ApiEnum.OPEN_TOKEN: new_current_user = _get_or_create_user(current__user_name) if new_current_user: ApiEnum.TOKEN = new_current_user.get("token") ApiEnum.OPEN_TOKEN = new_current_user.get("openToken") current_user_info ...[truncated 3581 chars]- Remediation
View remediation
Remediation Suggestions
-
Remove
--open-idfrom the public executable. If identity selection is operationally necessary, accept it only from a trusted, authenticated platform context rather than command-line input. -
Replace identifier-only silent login with a signed, short-lived identity assertion. The server should verify:
- the assertion issuer;
- the intended audience;
- expiration and replay protection;
- cryptographic integrity;
- that the asserted subject matches the requested account.
-
Require authenticated service credentials for the login or token-exchange endpoint. Do not issue account tokens solely from a caller-supplied username, mobile number, or OpenID.
-
Disable automatic registration during ordinary analysis and history requests. Account provisioning should use a separate authenticated workflow.
-
Bind every resulting token to the authenticated upstream subject and reject attempts to select a different identity.
-
Validate authorization server-side for report listing, media analysis, and pet enrollment. Do not rely only on client-provided identity fields such as
pnaUserName. -
Minimize bearer-token persistence. If local caching is required:
- store tokens in an OS-protected credential store;
- apply restrictive file permissions;
- encrypt tokens at rest;
- use short expiration periods and rotation;
- delete invalid or expired tokens promptly.
-
Add regression tests confirming that an arbitrary
--open-idcannot obtain tokens, access reports, submit analysis, or enroll data for another account.
-
