T09 · Insecure Skill Coding Practices
- Location
scripts/generate_infographic.py:396- Finding
Unvalidated Remote URL Allows Unrestricted Network Requests and Arbitrary Content Downloads
- Content
View full analysis
Optional[str]: if isinstance(node, str): if node.startswith("http://") or node.startswith("https://"): return node return None if isinstance(node, list): for item in node: url = deep_find_first_url(item) if url: return url return None if isinstance(node, dict): for key, value in node.items(): if "url" in key.lower() and isinstance(value, str): if value.startswith("http://") or value.startswith("https://"): return value url = deep_find_first_url(value) if url: return url return None ``` ```python def download_file(url: str, output_path: Path, timeout: int = 120) -> None: req = request.Request(url=url, method="GET") try: with request.urlopen(req, timeout=timeout) as resp: data = resp.read() except Exception as exc: raise RuntimeError(f"failed to download image: {exc}") from exc output_path.write_bytes(data) ``` ### Technical Analysis The script recursively accepts the first string beginning with `http://` or `https://` anywhere in the image-generation service response. It does not verify that the URL belongs to an expected DashScope or Alibaba image-storage domain. The selected URL is passed directly to `urllib.request.urlopen()`, which may follow redirects. The implementation does not: - Require HTTPS. - Restrict destination hostnames. - reject loopback, private, link-local, or cloud metadata addresses. - Revalidate destinations after redirects or DNS resolution. - Verify that the response is an image. - Vali ...[truncated 2326 chars]- Remediation
View remediation
