T09 · Insecure Skill Coding Practices
- Location
src/verify.js:14- Finding
Arbitrary URL Fetching Enables Server-Side Request Forgery
- Content
View full analysis
{ const protocol = url.startsWith('https') ? https : http; const timeout = options.timeout || 10000; const req = protocol.get(url, { headers: { 'User-Agent': 'ABN-LinkVerifier/1.0 (Agent Backlink Network)', 'Accept': 'text/html,application/xhtml+xml', ...options.headers }, timeout }, (res) => { // Handle redirects if (res.statusCode >= 300 && res.statusCode < 400 && res.headers.location) { const redirectUrl = res.headers.location.startsWith('http') ? res.headers.location : new URL(res.headers.location, url).href; return fetchPage(redirectUrl, options).then(resolve).catch(reject); } ``` ### Technical Analysis The backlink verifier sends server-side HTTP requests to a caller-controlled `pageUrl` without validating the destination hostname or resolved IP address. It does not reject loopback, private, link-local, reserved, multicast, or cloud metadata addresses. Redirect destinations are also followed without validation. Consequently, validating only an initial public URL outside this function would not be sufficient: an attacker-controlled public endpoint could redirect the verifier to an internal address. The choice of request module is based on `url.startsWith('https')` rather than strict parsing and scheme allowlisting. This further weakens URL validation and makes malformed or unexpected inputs harder to handle safely. ### Attack Path 1. An attacker supplies a backlink verification URL, either directly or through deal data consumed by an agent. 2. The agent calls `verifyBacklink(pageUrl, targetDomain)`. 3. `verifyBacklink()` passes the attacker-controlled URL to ...[truncated 1130 chars]- Remediation
View remediation
