T09 · Insecure Skill Coding Practices
- Location
scripts/fetch_holidays.py:226- Finding
Unvalidated Search Result URL Enables Server-Side Request Forgery
- Content
View full analysis
str: headers = { 'User-Agent': 'Mozilla/5.0 (Windows NT 10.0; Win64; x64) ' 'AppleWebKit/537.36 (KHTML, like Gecko) ' 'Chrome/120.0.0.0 Safari/537.36', 'Accept': 'text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8', 'Accept-Language': 'zh-CN,zh;q=0.9', } req = urllib.request.Request(url, headers=headers) try: with urllib.request.urlopen(req, timeout=30) as response: html_content = response.read().decode('utf-8') return extract_chinese_text(html_content) # Line 555: Unvalidated URL reaches the request function content = fetch_notice_content(url) ``` ### Technical Analysis The destination URL is obtained from a remotely supplied search API response and passed directly to `urllib.request.Request` and `urllib.request.urlopen`. The implementation does not validate: - The URL scheme. - The destination hostname. - The destination port. - Embedded credentials. - Whether the hostname resolves to a loopback, private, link-local, or otherwise restricted address. - Redirect destinations followed by `urllib`. - Whether the destination remains within the expected `gov.cn` domain. Consequently, compromise or manipulation of the search response could cause the script to request an attacker-selected destination. An allowed initial destination could also redirect the request to an internal or otherwise prohibited endpoint because redirect targets are not independently validated. The returned response is processed by ...[truncated 1955 chars]- Remediation
View remediation
