T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:16- Finding
Ambient Browser Authentication Used to Bypass an API Access Denial
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 16–20
Vulnerability Type:T05: Unauthorized Access and Privilege Escalation
Risk Level: MediumVulnerable Code
markdown 1) **Pull DevOps workitems** - Use browser session if direct API returns 403. - Endpoint: `/projex/api/workitem/workitem/list?_input_charset=utf-8` - Header: `x-yunxiao-token: $DEVOPS_TOKEN` - Page size 200, iterate all pages.Technical Analysis
An HTTP 403 response is an explicit access-control decision. The instruction directs the Agent to respond to that denial by switching from the supplied DevOps token to an authenticated browser session.
The browser session may contain cookies or other credentials with broader permissions than the dedicated token. This credential-context switch can defeat least-privilege isolation and cause requests to be executed under the interactive user's identity rather than a narrowly scoped service identity.
The instruction does not require explicit confirmation before using browser credentials, verify that the browser session belongs to the intended account, or constrain the browser session to a particular project and permission scope.
Attack Path
- The Agent sends a DevOps API request using
DEVOPS_TOKEN. - The API rejects the request with HTTP 403.
- Following the Skill instruction, the Agent switches to an existing authenticated browser session.
- The browser supplies ambient authentication credentials with potentially broader privileges.
- The Agent retrieves work-item data under the browser user's authorization context.
- Retrieved data is processed and may subsequently be included in a report sent to EMOP.
Impact Assessment
Successful exploitation or accidental misuse could expose DevOps work-item data that the dedicated token was not authorized to access. The effective privilege level is limited by the active browser user's DevOps permissions, which may include access to additional pro ...[truncated 252 chars]
- The Agent sends a DevOps API request using
- Remediation
View remediation
Remediation Suggestions
- Remove the automatic browser-session fallback and fail closed when the API returns HTTP 403.
- Require explicit user approval before changing authentication contexts.
- Use a dedicated, least-privilege service credential restricted to the required project, view, and read operations.
- Diagnose and correct token permissions rather than bypassing the denial through ambient browser credentials.
- Validate the destination origin, project ID, and requested resource before every authenticated request.
- If browser authentication is operationally required, use an isolated browser profile dedicated to this workflow and verify the authenticated account and authorization scope before retrieving data.
- Record the authentication method and approved scope in an audit log without recording tokens or session cookies.
