T09 · Insecure Skill Coding Practices
- Location
scripts/grok_imagine.py:38- Finding
Arbitrary Local File Disclosure Through Unvalidated Image Upload
- Content
View full analysis
dict: data = json.dumps(payload).encode("utf-8") req = request.Request( url, data=data, headers={ "Authorization": f"Bearer {api_key}", "Content-Type": "application/json", }, method="POST", ) try: with request.urlopen(req, timeout=300) as resp: return json.loads(resp.read().decode("utf-8", errors="replace")) except error.HTTPError as e: body = e.read().decode("utf-8", errors="replace") raise RuntimeError(f"HTTP {e.code}: {body}") except error.URLError as e: raise RuntimeError(f"Request failed: {e}") def image_to_data_uri(path: Path) -> str: mime, _ = mimetypes.guess_type(path.name) if not mime: mime = "image/png" raw = path.read_bytes() return f"data:{mime};base64,{base64.b64encode(raw).decode('ascii')}" ``` ```python def build_edit_image_payload(paths: list[str], urls: list[str]) -> list[dict] | dict: refs: list[dict] = [] for p in paths: uri = image_to_data_uri(Path(p)) refs.append({"url": uri, "type": "image_url"}) for u in urls: refs.append({"url": u, "type": "image_url"}) if not refs: raise RuntimeError("Provide at least one --image or --image-url for edit mode") if len(refs) == 1: return refs[0] if len(refs) > 3: raise RuntimeError("xAI image edit supports up to 3 source images") return refs def cmd_edit(args) -> int: image_payload = build_edit_image_payload(args.image or [], args.image_url or []) payload = { "model": args.model, "prompt": args.prompt, "image": image_payload, "n": args ...[truncated 3082 chars]- Remediation
View remediation
