T09 · Insecure Skill Coding Practices
- Location
scripts/bridge-server.mjs:124- Finding
Unauthenticated Local Bridge Permits Arbitrary Code Execution in EasyEDA
- Content
View full analysis
{ // CORS res.setHeader('Access-Control-Allow-Origin', '*'); res.setHeader('Access-Control-Allow-Methods', 'POST, GET, OPTIONS'); res.setHeader('Access-Control-Allow-Headers', 'Content-Type'); if (req.method === 'OPTIONS') { res.writeHead(204); res.end(); return; } ``` From `scripts/bridge-server.mjs:198-219`: ```javascript // Execute code on EDA if (req.method === 'POST' && req.url === '/execute') { let body = ''; for await (const chunk of req) body += chunk; try { const payload = JSON.parse(body); const code = payload.code; const windowId = payload.windowId; // optional, uses active window if not specified if (!code || typeof code !== 'string') { res.writeHead(400, { 'Content-Type': 'application/json' }); res.end(JSON.stringify({ error: 'Missing "code" field (string)' })); return; } const result = await executeOnEda(code, windowId); res.writeHead(200, { 'Content-Type': 'application/json' }); res.end(JSON.stringify({ success: true, result, windowId: windowId || activeEdaWindowId })); } catch (err) { ``` From `scripts/bridge-server.mjs:228-230`: ```javascript // ─── WebSocket Server ────────────────────────── ...[truncated 5285 chars]- Remediation
View remediation
