T09 · Insecure Skill Coding Practices
- Location
scripts/run.py:48- Finding
Unrestricted API Endpoint Allows Credential and Medical-Data Exfiltration
- Content
View full analysis
Vulnerability Details
File Location:
scripts/run.py:48-55andscripts/run.py:221-229
Vulnerability Type: Unrestricted remote endpoint configuration and sensitive-data disclosure
Risk Level: HighVulnerable Code
python def make_llm_caller(appkey: str, base: str = DEFAULT_LLM_BASE, model: str = DEFAULT_LLM_MODEL, timeout: int = 0): url = f"{base.rstrip('/')}/chat/completions" headers = {"Authorization": f"Bearer {appkey}"} def llm(messages: List[Dict[str, str]]) -> str: payload = {"model": model, "messages": messages, "temperature": 0} resp = _http_post(url, payload, headers, timeout=timeout)The endpoint is accepted directly from the command line and passed to the caller without validation:
python parser.add_argument("--base", default=DEFAULT_LLM_BASE, help=f"Internal model base URL (default: {DEFAULT_LLM_BASE}).") parser.add_argument("--model", default=DEFAULT_LLM_MODEL, help=f"Model name (default: {DEFAULT_LLM_MODEL}).") parser.add_argument("--timeout", type=int, default=0, help="HTTP timeout in seconds; 0 waits indefinitely.") parser.add_argument("--output", default="", help="Output file path; the default is standard output.") parser.add_argument("--encoding", default="utf-8", help="Input encoding; the default is UTF-8.") return parser.parse_args() # ... llm = make_llm_caller(args.appkey, args.base, args.model, args.timeout)Technical Analysis
The user-controlled
--baseargument determines the destination of the LLM request. The application attaches the supplied API key as a bearer token and includes the complete health report in the request body. It does not enforce HTTPS, validate the hostname, compare the destination against an allowlist, or prevent credentials intended for the default service from being forwarded to another origin.This creates a credential-forwarding and sensitive-data exfiltration vulnerability. An attacker ...[truncated 1527 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the
--baseoverride from production distributions unless endpoint customization is an explicit requirement. - Maintain an exact allowlist of trusted HTTPS origins and reject all other schemes, hosts, ports, user-information components, and redirects.
- Parse endpoints with
urllib.parse.urlparseand requirescheme == "https"and an approved normalized hostname. - Ensure the HTTP client does not follow redirects that cross to a different origin while retaining the authorization header.
- Bind credentials to a specific service or audience where the authentication platform supports scoped or audience-restricted tokens.
- Do not send a credential configured for the default service to a custom endpoint. Require a separately supplied credential after an explicit warning if custom endpoints must be supported.
- Add automated tests covering HTTP endpoints, lookalike domains, embedded user information, unexpected ports, subdomain confusion, and cross-origin redirects.
- Remove the
