T05 · Unauthorized Access and Privilege Escalation
- Location
SERVER_README.md:10- Finding
Unauthenticated API-key-backed proxy exposed on all network interfaces
- Content
View full analysis
SearchResponse: return search_places(request) @app.get("/places/{place_id}", response_model=PlaceDetails) def places_details(place_id: str) -> PlaceDetails: return get_place_details(place_id) @app.post("/locations/resolve", response_model=LocationResolveResponse) def locations_resolve(request: LocationResolveRequest) -> LocationResolveResponse: return resolve_locations(request) ``` ```python # src/local_places/main.py:62-65 if __name__ == "__main__": import uvicorn uvicorn.run("local_places.main:app", host="0.0.0.0", port=8000) ``` ### Technical Analysis The application exposes all Google Places proxy operations without authentication, authorization, or rate limiting. Both the documented startup command and the direct Python entry point bind the service to `0.0.0.0`, making it available through every network interface permitted by the host firewall. Each request is subsequently authenticated to Google using the server owner's `GOOGLE_PLACES_API_KEY`. Consequently, any network client that can reach port 8000 can indirectly exercise the authority and quota associated with that credential. This exceeds the minimum privileges necessary for the declared localhost-only Skill functionality in `SKILL.md`, which instructs clients to use `127.0.0.1`. The documented use of Uvicorn's `--reload` option also unnecessari ...[truncated 1337 chars]- Remediation
View remediation
