T09 · Insecure Skill Coding Practices
- Location
scripts/vendor/cli.mjs:9633- Finding
Unauthenticated and Unbounded Local Render Session Endpoints
- Content
View full analysis
{ try { const requestUrl = new URL(req.url ?? "/", "http://127.0.0.1"); if (req.method === "GET" && requestUrl.pathname === "/favicon.ico") { res.writeHead(204, noStoreHeaders()); res.end(); return; } if (req.method === "GET" && requestUrl.pathname === "/") { sendText(res, 200, buildHtmlPage(), "text/html; charset=utf-8"); return; } if (req.method === "GET" && requestUrl.pathname === "/renderer.js") { sendText(res, 200, rendererJs, "text/javascript; charset=utf-8"); return; } if (req.method === "GET" && requestUrl.pathname === "/job") { sendJson(res, 200, payload); return; } if (req.method === "POST" && requestUrl.pathname === "/result") { const bytes = await readRequestBytes(req); const mimeType = String(req.headers["content-type"] ?? "").trim() || (payload.format === "svg" ? "image/svg+xml" : "image/png"); await mkdir2(path4.dirname(outputPath), { recursive: true }); await writeFile2(outputPath, bytes); const done = { schema: "kmind-cli-render-session@v1", status: "done", format: payload.format, outputPath, byteLength: bytes.byteLength, mimeType }; sendJson(res, 200, done); settleResult?.({ kind: "success", done }); return; } if (req.method === "POST" && request ...[truncated 4332 chars]- Remediation
View remediation
