T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/bridge_server.py:31- Finding
Unauthenticated Local WebSocket Bridge Permits Browser Session Control and Cookie Extraction
- Content
View full analysis
None: try: raw = await asyncio.wait_for(ws.recv(), timeout=10) except (asyncio.TimeoutError, Exception) as e: logger.warning("Handshake timed out or failed: %s", e) return try: msg = json.loads(raw) except json.JSONDecodeError: return role = msg.get("role") if role == "extension": await self._handle_extension(ws) elif role == "cli": await self._handle_cli(ws, msg) else: logger.warning("Unknown role: %s", role) ``` ```python # scripts/bridge_server.py:71-101 async def _handle_cli(self, ws: ServerConnection, msg: dict) -> None: if msg.get("method") == "ping_server": await ws.send(json.dumps({ "result": {"extension_connected": self._extension_ws is not None} })) return if not self._extension_ws: await ws.send(json.dumps({ "error": "Extension is not connected" })) return msg_id = str(uuid.uuid4()) msg["id"] = msg_id loop = asyncio.get_event_loop() future: asyncio.Future[Any] = loop.create_future() self._pending[msg_id] = future await self._extension_ws.send(json.dumps(msg)) try: result = await asyncio.wait_for(future, timeout=90.0) await ws.send(json.dumps(result)) ``` ```javascript // extension/background.js:23-45 function connect() { if (ws && (ws.readyState === WebSocket.CONNECTING || ws.readyState === WebSocket.OPEN)) return; ws = new WebSocket(BRIDGE_URL); ws.onopen = ( ...[truncated 4999 chars]- Remediation
View remediation
