T09 · Insecure Skill Coding Practices
- Location
scripts/emr_qc_impl.py:58- Finding
Unrestricted API endpoint can receive bearer credentials and medical-record data
- Content
View full analysis
str: payload = {"model": model, "messages": messages, "temperature": 0} resp = _http_post(url, payload, headers, timeout=timeout) ``` The endpoint is supplied through unrestricted command-line arguments in both entry points: ```python parser.add_argument( "--base", default=DEFAULT_LLM_BASE, help=f"LLM base URL (default: {DEFAULT_LLM_BASE}).", ) ``` ### Technical Analysis The application constructs the destination URL directly from the user-controlled `base` value. It does not validate the URL scheme, hostname, port, resolved address, or final destination. The resulting request contains: - The HiVoice bearer credential in the `Authorization` header. - Medical-record content embedded in the LLM messages. - The configured model identifier. Consequently, a malicious or incorrectly supplied `--base` argument can redirect both the credential and sensitive medical data to an attacker-controlled server. Plain HTTP is also accepted, allowing network observers to intercept the request. Because `urllib.request.urlopen` can access destinations reachable from the host, the same behavior can be used to make requests to internal, loopback, or link-local services. The request format is fixed to an HTTP POST, but it still exposes a server-side request forgery surface if an untrusted party can influence launch parameters. ### Attack Path 1. An attacker influences a wrapper script, deployment ...[truncated 1362 chars]- Remediation
View remediation
