T09 · Insecure Skill Coding Practices
- Location
scripts/topmediai_api.py:20- Finding
Unrestricted API Base URL Enables Credential and User-Content Exfiltration
- Content
View full analysis
Vulnerability Details
File Location:
scripts/topmediai_api.py:20-22, 107-125, 153-157, 241-246, 265-271
Vulnerability Type: Unvalidated network destination for sensitive requests
Risk Level: HighVulnerable Code
python BASE_URL = os.environ.get("TOPMEDIAI_BASE_URL", "https://api.topmediai.com") DEFAULT_KEY = os.environ.get("TOPMEDIAI_API_KEY") DEBUG_MODE = str(os.environ.get("TOPMEDIAI_DEBUG", "0")).lower() in {"1", "true", "yes", "on"}python def _headers(api_key: Optional[str] = None) -> Dict[str, str]: key = api_key or DEFAULT_KEY if not key: raise RuntimeError( "TOPMEDIAI_API_KEY not configured. Edit: {} and set TOPMEDIAI_API_KEY=YOUR_KEY." "Get/purchase a key at https://www.topmediai.com/api/basic-information/interface-key/".format(_ENV_PATH) ) return {"x-api-key": key, "Content-Type": "application/json"} def generate_lyrics(prompt: str, api_key: Optional[str] = None) -> Dict[str, Any]: url = f"{BASE_URL}/v1/lyrics" headers = _headers(api_key) payload = {"prompt": prompt} _debug_request("POST", url, headers=headers, payload=payload) try: r = requests.post(url, json=payload, headers=headers, timeout=60)python def generate_music( action: str = "auto", prompt: Optional[str] = None, lyrics: Optional[str] = None, title: str = "", style: str = "Pop", mv: str = "v5.0", instrumental: int = 0, gender: str = "male", api_key: Optional[str] = None, ) -> Dict[str, Any]: url = f"{BASE_URL}/v3/music/generate"python headers = _headers(api_key) _debug_request("POST", url, headers=headers, payload=data) try: r = requests.post(url, json=data, headers=headers, timeout=120)Technical Analysis
The API client obtains
TOPMEDIAI_BASE_URLdirectly from the process environment or project ...[truncated 1867 chars]- Remediation
View remediation
Remediation Suggestions
- Remove
TOPMEDIAI_BASE_URLcustomization if alternate API hosts are not strictly required. - Otherwise, parse the value with
urllib.parse.urlparseand require:- The
httpsscheme. - The exact approved hostname
api.topmediai.com. - No embedded username or password.
- An approved port, normally
443.
- The
- Reject IP literals, unexpected subdomains, URL fragments, and malformed authorities.
- Build endpoint paths relative to a trusted, hardcoded origin.
- Before attaching
x-api-key, verify that the final request URL still belongs to the approved origin. - Disable redirects for authenticated requests or validate every redirect destination before forwarding credentials.
- Document that proxy and environment configuration must be trusted.
- Rotate the API key if it may already have been used with an untrusted base URL.
- Remove
