T09 · Insecure Skill Coding Practices
- Location
scripts/html2docx.py:2049- Finding
Unrestricted Remote Image Fetching Enables Blind SSRF
- Content
View full analysis
` attribute is requested from the environment running the converter. The implementation does not: - Require explicit authorization for network access. - Restrict destinations to approved hosts. - Reject loopback, private, link-local, multicast, or reserved IP addresses. - Protect cloud instance metadata endpoints. - Revalidate redirect destinations. - Prevent DNS rebinding. - Restrict ports or URL credentials. Fetching external images can support HTML-to-DOCX conversion, but unrestricted network access exceeds the minimum privilege required. Embedded data or approved local image inputs can provide the core conversion functionality without granting arbitrary outbound access. Because request errors are suppressed, this is primarily a blind SSRF primitive. Nevertheless, differences in processing time or whether a valid image is inserted may provide limited information about internal resources. ### Attack Path 1. An attacker supplies or influences the HTML being converted. 2. The attacker inserts an image referencing an internal destination, such as: ```html``` 3. The converter processes the image and passes its `src` att ...[truncated 1153 chars]
- Remediation
View remediation
