T09 · Insecure Skill Coding Practices
- Location
scripts/mimo_asr_api.py:32- Finding
TLS Certificate Verification Disabled for Audio Transcription Requests
- Content
View full analysis
Vulnerability Details
File Location:
scripts/mimo_asr_api.py, lines 32-53
Vulnerability Type: Improper TLS certificate validation
Risk Level: HighVulnerable Code
python def upload_audio(filepath): """Upload an audio file to the Gradio server.""" with open(filepath, 'rb') as f: r = requests.post( f"{API_BASE}/gradio_api/upload", files={'files': f}, timeout=120, verify=False ) r.raise_for_status() data = r.json() if isinstance(data, list) and len(data) > 0: return data[0] return data def call_transcribe(audio_data_url, language_tag): """Call the transcription API and return its event ID.""" payload = {"data": [audio_data_url, None, language_tag]} r = requests.post( f"{API_BASE}/gradio_api/call/transcribe", json=payload, timeout=30, verify=False ) r.raise_for_status() data = r.json() return data.get('event_id') def poll_result(event_id): """Poll the SSE endpoint for the transcription result.""" url = f"{API_BASE}/gradio_api/call/transcribe/{event_id}" with requests.get( url, stream=True, timeout=180, verify=False ) as r:The original source uses
verify=Falseon the requests at lines 32, 43, and 53.Technical Analysis
The
verify=Falseoption disables validation of the remote server's TLS certificate. Although the URLs use HTTPS, the client does not verify that it is communicating with the legitimate Hugging Face-hosted service.An attacker capable of intercepting network traffic can present an arbitrary certificate without causing the client to reject the connection. The attacker can consequently observe or modify the upload request, transcription initiation request, and streamed transcription response.
The vulnerability affects ...[truncated 1409 chars]
- Remediation
View remediation
Remediation Suggestions
Remove
verify=Falsefrom all Requests calls and rely on certificate verification by default:python r = requests.post( f"{API_BASE}/gradio_api/upload", files={'files': f}, timeout=120 ) r = requests.post( f"{API_BASE}/gradio_api/call/transcribe", json=payload, timeout=30 ) with requests.get(url, stream=True, timeout=180) as r: r.raise_for_status() # Process the response.Additional hardening should include:
- Keep the operating system and Python CA certificate bundle current.
- If a private CA is genuinely required, pass the path of a narrowly scoped trusted CA bundle through
verify="/path/to/ca-bundle.pem"rather than disabling verification. - Do not suppress TLS warnings as a substitute for certificate validation.
- Call
raise_for_status()on the polling response before processing streamed data. - Document that audio is transmitted to a third-party cloud service and advise users not to upload sensitive recordings without authorization.
