T09 · Insecure Skill Coding Practices
- Location
scripts/index.js:96- Finding
Appian API Key Disclosure Through Unvalidated Artifact URLs
- Content
View full analysis
Vulnerability Details
File Location:
scripts/index.js, lines 96-97 and 137-149
Vulnerability Type: Credential disclosure through server-controlled outbound requests
Risk Level: HighVulnerable Code
js async function downloadArtifact(url, apiKey, destDir, fallbackName) { const res = await fetch(url, { headers: { 'appian-api-key': apiKey } });The unvalidated URLs are passed to this function as follows:
js if (opts.downloadLog && data.deploymentLogUrl) { process.stderr.write('\nDownloading log...\n'); const f = await downloadArtifact(data.deploymentLogUrl, credentials.apiKey, destDir, `${deploymentUuid}-log.txt`); if (f) downloads.push(f); } if (opts.downloadZip && data.packageZip) { process.stderr.write('\nDownloading package ZIP...\n'); const f = await downloadArtifact(data.packageZip, credentials.apiKey, destDir, `${deploymentUuid}.zip`); if (f) downloads.push(f); }Technical Analysis
deploymentLogUrlandpackageZiporiginate in the deployment API response. The script passes these values directly tofetch()and unconditionally attaches the sensitiveappian-api-keyheader. It does not validate the URL scheme, hostname, port, or origin before transmitting the credential.Consequently, a compromised, malicious, or incorrectly configured Appian endpoint can return an artifact URL under an attacker-controlled origin. When an artifact download is requested, the script sends the Appian API key to that origin. Redirect handling also requires attention because
fetch()follows redirects by default; credential behavior across redirects should not be relied upon as the primary protection.This network transmission is necessary only when the artifact endpoint is trusted and actually requires the Appian credential. Sending the credential to arbitrary API-provided origins exceeds the minimum privileges required for artifact ret ...[truncated 1325 chars]
- Remediation
View remediation
Remediation Suggestions
- Parse every artifact URL with
new URL(url)and reject malformed URLs. - Require HTTPS for both the configured Appian endpoint and artifact endpoints.
- Maintain an explicit allowlist of trusted artifact origins. Prefer requiring the artifact URL origin to equal
new URL(APPIAN_BASE_URL).origin. - Attach
appian-api-keyonly when the destination is an approved origin that requires this credential. Do not attach it to cross-origin or presigned download URLs. - Disable automatic redirects with
redirect: 'manual', or validate each redirect destination before issuing another credential-bearing request. - Reject URLs containing unexpected credentials, ports, protocols, or hostnames.
- Document the permitted artifact hosts and credential-forwarding policy accurately.
- Apply server-side least privilege to the API key and rotate any key that may have been disclosed.
- Parse every artifact URL with
