T09 · Insecure Skill Coding Practices
- Location
scripts/stepone_client.py:176- Finding
API Key May Be Disclosed Through Cross-Origin HTTP Redirects
- Content
View full analysis
Vulnerability Details
File Location:
scripts/stepone_client.py, lines 176-181; related credential attachment at lines 164-165 and request construction at lines 197-200 and 382-389
Vulnerability Type: Cross-origin credential disclosure through unrestricted redirect handling
Risk Level: MediumVulnerable Code
python def open_request(req: urllib.request.Request, timeout: float): scheme = urllib.parse.urlsplit(req.full_url).scheme if scheme not in {"https", "http"}: raise ClientError("request URL must use HTTP or HTTPS") # The URL scheme is allowlisted immediately above. return urllib.request.urlopen(req, timeout=timeout) # nosec B310Authentication is attached before this function is called:
python if authenticated: headers["X-API-Key"] = api_key()Technical Analysis
The client validates only the initial API URL. It then invokes
urllib.request.urlopen, whose default opener automatically follows HTTP redirects. The destination of each redirect is not revalidated against the original scheme and origin.Because
X-API-Keyis supplied as a normal request header, redirect processing may preserve it when constructing the redirected request. A redirect from the validated API endpoint to another origin can consequently disclose the Stepone AI API key. The same transport is used by ordinary authenticated API operations and transcript streaming.The sensitive network transmission detected by the pre-scan is otherwise necessary for the declared telephone functionality: phone numbers, call instructions, call identifiers, and transcripts are sent to or retrieved from the documented Stepone AI API. The issue is that the credential can potentially travel beyond that intended endpoint.
Attack Path
- An authenticated command such as
call,callinfo,balance, orstreamis invoked. - The client creates a request containing the user's `X-API-Key ...[truncated 1271 chars]
- An authenticated command such as
- Remediation
View remediation
Remediation Suggestions
- Disable automatic redirect handling for authenticated requests and reject redirect responses by default.
- If redirects are operationally required, implement a custom
HTTPRedirectHandlerthat validates every destination before following it. - Permit redirects only when the destination has the same normalized scheme, hostname, and effective port as the original API endpoint.
- Reject HTTPS-to-HTTP downgrades under all production configurations.
- Remove
X-API-Key,Authorization, cookies, idempotency keys, and other sensitive headers before any cross-origin redirect. - Apply identical redirect controls to both standard JSON requests and SSE transcript streaming.
- Add automated tests covering same-origin redirects, cross-origin redirects, HTTPS downgrades, and custom API-base configurations.
- Rotate the API key if logs or runtime evidence indicate that an authenticated request previously followed an untrusted redirect.
