T09 · Insecure Skill Coding Practices
- Location
scripts/verify-inbound-setup.sh:45- Finding
Incomplete SSRF Protection in Webhook Endpoint Verification
- Content
View full analysis
&1 || echo "000") ``` ### Technical Analysis The URL check validates only the URL's textual structure and HTTPS scheme. It does not resolve and classify the destination address before `curl` connects. Consequently, the expression accepts destinations such as: ```text https://127.0.0.1:8443/ https://internal-service.example/ https://service.internal/ ``` A publicly resolvable hostname can also resolve to a loopback, private, link-local, or otherwise reserved address. DNS rebinding may create a time-of-check/time-of-use discrepancy between validation and connection. Using HTTPS does not prevent SSRF. Internal services may use HTTPS with publicly trusted, locally trusted, or otherwise accepted certificates. The script therefore does not fulfill its comment that internal destinations are blocked. The request is a fixed multipart POST, and the response body is discarded. This limits the issue to blind SSRF with an HTTP-st ...[truncated 1417 chars]- Remediation
View remediation
