T09 · Insecure Skill Coding Practices
- Location
scripts/emr_qc_impl.py:53- Finding
Configurable API Endpoint Can Expose the AppKey and Medical Records
- Content
View full analysis
str: payload = {"model": model, "messages": messages, "temperature": 0} resp = _http_post(url, payload, headers, timeout=timeout) ``` The destination is supplied directly through the command line: ```python parser.add_argument( "--base", default=DEFAULT_LLM_BASE, help=f"大模型 base URL(默认:{DEFAULT_LLM_BASE})。", ) ``` ### Technical Analysis The `--base` argument is accepted without validating the URL scheme, hostname, port, or resolved IP address. The resulting URL receives: - The supplied AppKey in the `Authorization: Bearer` header. - Medical-record fields embedded in the request messages. - Any other prompt data generated by the quality-control workflow. Consequently, an invocation wrapper, configuration injection, or operator trick can change `--base` to an attacker-controlled server. The implementation does not require HTTPS or restrict the destination to the documented HiVoice MaaS service. The same functionality can also be abused as a limited server-side request primitive when the program runs in an environment that can reach internal services. Because requests use a fixed POST path and JSON body, this is not unrestricted SSRF, but it can still disclose connectivity information or transmit credentials and medical information to internal or external destinations. ### Attack Path ...[truncated 1224 chars]- Remediation
View remediation
