T09 · Insecure Skill Coding Practices
- Location
scripts/download_images.sh:18- Finding
Unrestricted URL Retrieval Enables Server-Side Request Forgery and Local File Access
- Content
View full analysis
Vulnerability Details
File Location:
scripts/download_images.sh, lines 18-27
Vulnerability Type: Unrestricted external resource retrieval
Risk Level: HighVulnerable Code
bash # Download images for url in "${@:2}"; do filename=$(basename "$url" | sed 's/webp$/jpg/') # Download with Referer curl -H "Referer: https://www.xiaohongshu.com/" \ -o "$SAVE_DIR/$filename" "$url" # Copy to upload directory cp "$SAVE_DIR/$filename" "$UPLOAD_DIR/" echo "Downloaded: $filename" doneTechnical Analysis
Every URL supplied after the title argument is passed directly to
curl. The script does not validate the URL scheme, hostname, resolved IP address, response type, or response size.The caller is therefore not restricted to downloading images from Xiaohongshu. Depending on the protocols supported by the installed
curlbuild, a malicious caller can request:- Localhost or internal HTTP services.
- Cloud instance metadata endpoints.
- Private or link-local network addresses.
- Local files through the
file://scheme. - Arbitrarily large resources that consume local disk capacity.
- Non-image content that is subsequently placed in the upload staging directory.
The hardcoded
Refererheader does not constrain the destination and provides no SSRF protection. The retrieved data is written using the privileges of the user running the Skill.Attack Path
- An attacker controls or influences an image URL passed to
download_images.sh. - The attacker supplies a URL such as a localhost endpoint, private-network service, cloud metadata endpoint, or
file://resource. - The script passes the URL directly to
curl. curlretrieves the resource with the network and filesystem access available to the Skill process.- The response is stored under the archive directory and copied into
/tmp/openclaw/uploads. - The ret ...[truncated 681 chars]
- Remediation
View remediation
Remediation Suggestions
- Parse each URL before invoking
curl. - Permit only the
httpsscheme. - Maintain an explicit allowlist of approved Xiaohongshu image CDN hostnames.
- Reject embedded credentials, localhost names, IP literals, and destinations resolving to loopback, private, link-local, multicast, or reserved address ranges.
- If redirects are enabled in the future, validate every redirect destination against the same allowlist.
- Configure connection and transfer timeouts.
- Enforce a maximum response size.
- Download into a newly created temporary file and verify the content using an image decoder rather than trusting the extension or
Content-Typeheader. - Reject responses that are not valid supported image formats.
- Run the downloader with restricted network access and minimal filesystem permissions.
- Parse each URL before invoking
