T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/playwright-simple.js:11- Finding
Unrestricted Browser Navigation Enables Server-Side Request Forgery
- Content
View full analysis
'); process.exit(1); } (async () => { console.log('🚀 啟動 Playwright 簡單版爬蟲...'); const startTime = Date.now(); const browser = await chromium.launch({ headless: process.env.HEADLESS !== 'false' }); const page = await browser.newPage(); console.log(`📱 導航到: ${url}`); await page.goto(url, { waitUntil: 'domcontentloaded' }); ``` `scripts/playwright-stealth.js:22-22, 87-90`: ```js const url = process.argv[2]; ``` ```js const response = await page.goto(url, { waitUntil: 'domcontentloaded', timeout: 30000, }); ``` ### Technical Analysis Both scraper modes pass a caller-controlled URL directly to Playwright without validating its scheme, hostname, resolved IP address, port, or redirect destinations. The implementation does not block loopback, link-local, private, reserved, or cloud metadata addresses. Because Chromium makes the request from the machine running the Skill, the target is reached with the Agent host's network access rather than the external requester's access. The scripts subsequently extract page text and print it to standard output. This creates a practical SSRF primitive against HTTP services accessible from the host. Protocol validation is also absent. At minimum, navigation should be restricted to explicitly approved `http:` and `https:` destinations. Redirects must be validated separately because an initially public URL can redirect to an int ...[truncated 1174 chars]- Remediation
View remediation
