T09 · Insecure Skill Coding Practices
- Location
scripts/newsletter_detector.py:124- Finding
Untrusted unsubscribe URLs are presented as safe one-click actions
- Content
View full analysis
]+)>', list_unsub) http_match = re.search(r'<(https?://[^>]+)>', list_unsub) if http_match: unsub_info['method'] = 'link' unsub_info['link'] = http_match.group(1) elif mailto_match: unsub_info['method'] = 'email' unsub_info['email'] = mailto_match.group(1) ``` The extracted value is subsequently presented as an easy one-click action: ```python if easy: unsub = sender_info['unsubscribe'] if unsub['method'] == 'link': lines.append(f" Link: {unsub['link']}") elif unsub['method'] == 'email': lines.append(f" Email: {unsub['email']}") ``` ### Technical Analysis The `List-Unsubscribe` header and email body are controlled by the email sender. The implementation accepts any string matching an HTTP or HTTPS URL and propagates it into a prioritized unsubscribe report without validating: - The destination hostname or resolved IP address - Localhost, private, link-local, loopback, or reserved network ranges - Cloud metadata service addresses - Embedded credentials - Non-default ports - URL normalization or parser ambiguities - Redirect destinations - Whether the unsubscribe destination is associated with the sender's domain The report labels any successfully extracted method as an easy unsubscribe action and displays a success indicator. This creates an unsafe trust signal around attacker-controlled content. The current script only prints the URL and does not itself issue a network request. Exploitation therefore requires a user or downstream automation to follow the generated ...[truncated 2158 chars]- Remediation
View remediation
