T09 · Insecure Skill Coding Practices
- Location
scripts/transcribe.py:137- Finding
Unrestricted Media Download Enables Server-Side Request Forgery and Resource Exhaustion
- Content
View full analysis
{output_path}") headers = {"User-Agent": USER_AGENT} try: response = requests.get(video_url, headers=headers, stream=True, timeout=300) response.raise_for_status() with open(output_path, "wb") as f: for chunk in response.iter_content(chunk_size=8192): if chunk: f.write(chunk) print("视频下载完成") return True except Exception as e: print(f"下载视频失败: {e}") return False ``` The URL reaching this function can come directly from caller-supplied `parse_result` data: ```python # Get the video title to create the temporary directory. data = parse_result.get("data", {}) title = data.get("title", "未命名视频") tmp_dir = create_tmp_dir(title) final_result = { "parse_info": parse_result, "transcription": None } video_url = data.get("video_url") if video_url: temp_id = uuid.uuid4().hex video_file = tmp_dir / f"video_{temp_id}.mp4" audio_file = tmp_dir / f"audio_{temp_id}.mp3" try: if download_video(video_url, video_file): if extract_audio(video_file, audio_file): text = transcribe_audio(audio_file, api_key, model) final_result["transcription"] = text ``` ### Technical Analysis The application performs an outbound GET request to `video_url` without validating: - The URL scheme - The destination hostname - The destination's resolved IP address - Whether the destination is loopback, private, link-local, multicast, or a cloud ...[truncated 2487 chars]- Remediation
View remediation
