T09 · Insecure Skill Coding Practices
- Location
mch-demo-adult/server.py:684- Finding
Payment Endpoint Accepts and Retains Health Data Contrary to the Declared Privacy Boundary
- Content
View full analysis
str: # Compatibility path for requests containing health records. if data.get("profile") or data.get("reports"): return build_adult_record(data) skill = data.get("skill") or "personal-health-archive-trend" ``` The HTTP handler reads the complete request body and passes the parsed data to this function: ```python length = int(self.headers.get("Content-Length", 0) or 0) raw = self.rfile.read(length) if length else b"{}" try: data = json.loads(raw or b"{}") except Exception: data = {} ``` During initial order creation, the generated result is retained in the process-wide order store: ```python with _lock: _orders[out_trade_no] = { "paid": False, "content": execute_business(data), } ``` Consequently, a request containing a name, birth date, measurements, and medical reports is processed remotely and converted into an identifiable health record. The generated record remains in server memory until process termination or replacement. Base64 operations elsewhere in the file are used for payment signatures, payment payloads, and callback cryptography. No separate encoded health-data exfiltration channel was identified. The confirmed issue is the direct acceptance and processing of health data by the remote endpoint. ### At ...[truncated 1124 chars]- Remediation
View remediation
