T09 · Insecure Skill Coding Practices
- Location
scripts/upload_video.py:68- Finding
Unvalidated Remote-Controlled File Upload Destination
- Content
View full analysis
Vulnerability Details
File Location:
scripts/upload_video.py, lines 68–69 and 88–91
Vulnerability Type: Unvalidated upload URL / sensitive file disclosure
Risk Level: MediumVulnerable Code:
python upload_url = init_data["data"]["upload_url"] identity = init_data["data"]["identity"] # ... with open(file_path, 'rb') as f: req = urllib.request.Request(upload_url, data=f, headers=upload_headers, method="PUT") req.add_header("Content-Length", str(file_size)) with urllib.request.urlopen(req) as response: if response.getcode() not in (200, 201, 204): raise Exception(f"Failed to upload file. Status code: {response.getcode()}")Technical Analysis
The script obtains
upload_urlfrom the WayinVideo API response and uses it directly as the destination for the complete user-selected video. It does not validate the URL scheme, hostname, port, embedded credentials, or redirect destination.Uploading the selected video is necessary for the Skill's declared clipping functionality. However, trusting a remotely supplied destination without validation exceeds the minimum trust required. If the API response or upstream service is compromised, the response could direct the upload to an attacker-controlled host or an insecure HTTP endpoint.
Because
urllib.request.urlopenmay follow redirects, validating only the initial URL would also be insufficient unless redirect destinations are restricted.Attack Path
- A user invokes the Skill with a local video.
- The script sends an authenticated initialization request to the WayinVideo API.
- A compromised API, upstream component, or response path returns a malicious
upload_url. - The script accepts the URL without checking its scheme or destination.
- The script opens the selected local video and transmits its complete contents using an HTTP
PUT. - The attacker-controlled destination receives the vide ...[truncated 943 chars]
- Remediation
View remediation
Remediation Suggestions
- Parse
upload_urlbefore opening the local file. - Require the
httpsscheme and reject plaintext HTTP. - Reject embedded usernames or passwords, fragments, unexpected ports, malformed hostnames, and non-public or local-network destinations.
- Restrict the hostname to documented WayinVideo-approved storage domains. If dynamic storage providers are required, maintain an explicit and narrowly scoped allowlist.
- Disable automatic redirects for the upload or validate every redirect target against the same scheme and hostname policy.
- Resolve the destination carefully and block loopback, link-local, private, multicast, and cloud metadata address ranges to reduce DNS-rebinding and internal-network risks.
- Fail closed if URL validation cannot establish that the destination is approved.
- Consider displaying the validated destination and requesting explicit user confirmation when it differs from the expected provider domain.
- Document that local video content is transferred to a third-party service and state the applicable retention policy before upload.
- Add automated tests covering HTTP URLs, attacker-controlled hosts, embedded credentials, unexpected ports, redirect chains, DNS rebinding scenarios, and approved presigned storage URLs.
- Parse
