T09 · Insecure Skill Coding Practices
- Location
qweather.py:67- Finding
Unrestricted API Host Can Receive Signed Bearer Tokens
- Content
View full analysis
Dict: """发送API请求""" # 生成JWT token token = self._generate_jwt() # 构建URL url = f"https://{self.api_host}{endpoint}" # 设置headers headers = { "Authorization": f"Bearer {token}" } # 发送请求 response = self.session.get(url, headers=headers, params=params, timeout=10) response.raise_for_status() return response.json() ``` ### Technical Analysis The `QWEATHER_API_HOST` environment variable is used directly to construct the destination URL. The application does not verify that the resolved hostname is an approved QWeather domain. Every request generates a JWT signed with the configured private key and sends it in the `Authorization` header. An attacker who can modify the process environment or otherwise control the configuration can set `QWEATHER_API_HOST` to an attacker-controlled HTTPS host. The application would then send a valid, signed bearer token to that host. This runtime behavior does not enforce the `*.qweatherapi.com` endpoint restriction declared in the Skill metadata. Prefix-based or substring-based validation would not be sufficient because domains such as `qweatherapi.com.attacker.example` could bypass weak checks. Redirect handling is a ...[truncated 1289 chars]- Remediation
View remediation
str: if not host or any(char in host for char in "/:@?#"): raise ValueError("Invalid QWeather API host") normalized = host.rstrip(".").lower() approved_suffix = ".qweatherapi.com" if not normalized.endswith(approved_suffix): raise ValueError("API host must be a qweatherapi.com subdomain") return normalized ``` 4. Reject URL schemes, embedded credentials, ports unless explicitly required, IP literals, control characters, and path components in the host setting. 5. Disable redirects for credential-bearing requests: ```python response = self.session.get( url, headers=headers, params=params, timeout=10, allow_redirects=False, ) ``` 6. If redirects are operationally required, validate every redirect destination before forwarding the authorization header. 7. Prefer a fixed endpoint or a deployment-level allowlist instead of allowing arbitrary environment-controlled destinations. 8. Add tests covering malicious domains, including `qweatherapi.com.attacker.example`, `attacker-qweatherapi.com`, IP addresses, and credential-bearing URLs. ]]>
