T09 · Insecure Skill Coding Practices
- Location
src/qshare/cli.py:225- Finding
TryCloudflare Tunnel Exposes Unintended Sibling Files and Directory Listings
- Content
View full analysis
Vulnerability Details
File Location:
src/qshare/cli.py:225, 379-410
Vulnerability Type: Improper restriction of files served through a public tunnel
Risk Level: HighVulnerable code:
python server = ShareHTTPServer( ("127.0.0.1", port), partial(ShareHandler, directory=str(file_path.parent)), )python local_url = f"http://127.0.0.1:{resolved_port}/{source.name}" tunnel_process, tunnel_url = launch_trycloudflare_tunnel( local_url, timeout_seconds=min(ttl_seconds, 30), ) public_file_url = build_download_url(tunnel_url, source.name)Technical Analysis
The local HTTP server uses Python's
SimpleHTTPRequestHandlerwith the selected file's parent directory as its document root. Although the printed URL points to the selected filename, the handler does not enforce a single-file allowlist.The TryCloudflare tunnel forwards requests to the local HTTP server. Consequently, the remote request path is attacker-controlled, and an unauthenticated visitor can request other filenames or directories beneath the selected file's parent directory. Requests for directories can also invoke the handler's standard directory-listing behavior.
This crosses the intended authorization boundary from sharing one explicitly selected file to exposing additional local content. It also contradicts
SKILL.md, which directs the agent not to expose arbitrary local paths, directory listings, or additional files.Attack Path
- The user asks the Skill to share one local file through the default TryCloudflare workflow.
start_local_http_server()configures the selected file's entire parent directory as the HTTP document root.- The tunnel makes that local HTTP service reachable from the Internet.
- An unauthenticated visitor obtains the tunnel hostname from the shared URL.
- The visitor changes the URL path to
/, another known or guessed filename, or a child-directory p ...[truncated 652 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the generic
SimpleHTTPRequestHandlerbehavior with a dedicated handler that serves exactly one canonical URL path. - Return
404 Not Foundfor/, sibling filenames, child directories, URL-encoded path variations, and every path other than the authorized file. - Disable directory listing explicitly.
- Avoid using the selected file's parent directory as a general-purpose document root.
- Resolve and compare canonical paths before opening a file, ensuring the requested resource exactly equals the user-selected file.
- Add tests confirming that the selected URL succeeds while
/, sibling-file paths, nested paths, traversal forms, and encoded path variants are rejected.
- Replace the generic
