T09 · Insecure Skill Coding Practices
- Location
scripts/find-rss.sh:18- Finding
Unrestricted URL Fetching Enables Server-Side Request Forgery
- Content
View full analysis
Vulnerability Details
File Location:
scripts/find-rss.sh, lines 5, 18, 48, and 72–76
Vulnerability Type: Server-Side Request Forgery (SSRF)
Risk Level: HighVulnerable Code
bash URL="$1"bash # Fetch the page and extract RSS/Atom links echo "📄 Checking HTML for RSS link tags..." RSS_LINKS=$(curl -s -L "$URL" | grep -iE 'type="application/(rss|atom)"|rel="alternate"' | grep -iE 'href="[^"]*"' | sed 's/.*href="\([^"]*\)".*/\1/' | sort -u)bash # Extract domain DOMAIN=$(echo "$URL" | sed -E 's|(https?://[^/]+).*|\1|')bash for path in "${COMMON_PATHS[@]}"; do TEST_URL="${DOMAIN}${path}" STATUS=$(curl -s -o /dev/null -w "%{http_code}" -L "$TEST_URL" 2>/dev/null) if [ "$STATUS" = "200" ]; then # Check if it's actually an RSS/Atom feed CONTENT_TYPE=$(curl -s -I -L "$TEST_URL" 2>/dev/null | grep -i "content-type" | head -1)Technical Analysis
The script accepts a caller-controlled value as
URLand passes it directly tocurlwithout validating its scheme, hostname, resolved address, or destination port. It also enables automatic redirect following through-Lwithout validating each redirect target.Consequently, the script can be induced to request resources that should not be reachable through normal external website discovery, including:
- Loopback services such as
127.0.0.1orlocalhost - Private network addresses
- Link-local and cloud metadata addresses
- Local resources accessible through non-HTTP protocols supported by the installed
curl - Internal destinations reached through redirects from an initially public URL
After the initial request, the script derives a domain and probes multiple predictable RSS paths. This expands the issue from a single arbitrary request into limited service and endpoint reconnaissance against the selected host. HTTP status codes, content types, and extracted feed-like ...[truncated 1819 chars]
- Loopback services such as
- Remediation
View remediation
Remediation Suggestions
- Parse the supplied URL with a dedicated URL parser rather than regular expressions.
- Permit only explicitly supported schemes, preferably
httpsand, if required,http. Rejectfile,ftp,gopher, and every other scheme. - Reject URLs containing embedded credentials, malformed hosts, ambiguous numeric IP formats, or unsupported ports.
- Resolve the hostname before each request and reject all loopback, private, link-local, multicast, reserved, and unspecified IPv4 and IPv6 ranges.
- Explicitly block cloud metadata destinations, including link-local metadata addresses and deployment-specific metadata hostnames.
- Disable automatic redirects or validate the scheme, hostname, port, and resolved IP address of every redirect destination before following it.
- Account for DNS rebinding by validating resolved addresses at connection time and avoiding untrusted re-resolution between validation and connection.
- Pass a validated URL to
curlafter an option terminator and restrict protocols explicitly, for example with--proto '=http,https'. - Add connection and total request timeouts, response-size limits, and a maximum redirect count to reduce denial-of-service exposure.
- Run the skill in an egress-restricted sandbox that cannot access localhost, private networks, metadata services, or other sensitive destinations.
- Apply the same validation to the initial page request, every generated common-path URL, and every redirect target.
