T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/sport_analysis.py:199- Finding
Shared Fallback Identity Allows Cross-User Report Access
- Content
View full analysis
Vulnerability Details
File Location:
scripts/sport_analysis.py:199-204;skills/smyx_common/scripts/util.py:428-469;skills/smyx_common/scripts/util.py:619-623
Vulnerability Type: Broken user isolation through shared fallback identity
Risk Level: HighVulnerable Code
scripts/sport_analysis.py:199-204:python # Initialize the internal user identity. OpenIdUtil.resolve_current_open_id(args.open_id, use_current=bool(args.open_id)) if args.list: open_id = ConstantEnum.CURRENT__OPEN_ID result = show_analyze_list(open_id) print(result) exit(0)skills/smyx_common/scripts/util.py:428-469:python @classmethod def get_or_create_default_open_id(cls): from .dao import UserDao, User import uuid user_dao = UserDao() user = user_dao.get_first_default_user( cls.DEFAULT_PREFIX, cls.DEFAULT_USERNAME_LENGTH ) if user and user.username: return user.username for _ in range(10): username = cls.generate_default_open_id() if user_dao.get_by_username(username): continue now = datetime.now() user = User( id=uuid.uuid4().hex, username=username, realname=username, source=ConstantEnum.APP__SOURCE, del_flag=0, create_time=now, update_time=now ) user_dao.add(user) return username raise RuntimeError( "Failed to generate a default open-id after repeated collisions" ) @classmethod def resolve_current_open_id(cls, open_id=None, use_current=True): resolved_open_id = ( (open_id or "").strip() if isinstance(open_id, str) else open_id ) if not resolved_open_id and use_current: resolved_open_id = ( ConstantEnum.CURRENT__OPEN_ID or ConstantEnum.CURRENT__USER_NAME ) if not resolved_open_id: resolved_open_id = cls.get_api_key_file_open_id ...[truncated 3670 chars]- Remediation
View remediation
Remediation Suggestions
-
Require every analysis and history request in a multi-user deployment to carry a trusted, authenticated per-request identity.
-
Preserve identities initialized from trusted upstream context. In particular, do not set
use_current=Falsemerely because the hidden command-line argument is absent:
python OpenIdUtil.resolve_current_open_id( args.open_id, use_current=True )-
Remove the workspace-wide fallback identity from multi-user execution paths. If no authenticated identity is available, reject history queries instead of silently selecting the first local default user.
-
If anonymous analysis is required, generate an isolated identity scoped to the current authenticated principal or session. Do not use a single database record across unrelated callers.
-
Enforce ownership on the server. The backend should derive report ownership from an authenticated token or session rather than trusting the client-provided
pnaUserNamefield. -
Verify that report detail and export endpoints perform the same ownership checks as the report-list endpoint. A report identifier or export URL must not be sufficient to access another user’s report.
-
Add multi-user isolation tests covering:
- Two upstream users in one workspace
- Missing
--open-id - Environment-provided sender identities
- History-list access after each user submits an analysis
- Direct access to report detail and export links
-
Migrate or separate reports already stored under shared fallback identities where ownership can be established safely.
-
