T09 · Insecure Skill Coding Practices
- Location
scripts/fetch_page.py:39- Finding
Arbitrary URL Fetching Enables Server-Side Request Forgery
- Content
View full analysis
Tuple[str, requests.Response, List[str]]: notes = [] headers = {"User-Agent": DEFAULT_UA, "Accept-Language": "en-US,en;q=0.9"} try: response = requests.get(url, headers=headers, timeout=timeout) response.raise_for_status() return response.text, response, notes except requests.RequestException as exc: notes.append(f"requests failed: {exc}") raise ``` The browser fallback also navigates directly to the unvalidated URL: ```javascript (async () => { const argv = process.argv.slice(-2); const url = argv[0]; const waitMs = Number(argv[1] || 2500); const browser = await chromium.launch({ headless: true }); const page = await browser.newPage({ userAgent: "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36" }); await page.goto(url, { waitUntil: "domcontentloaded", timeout: 30000 }); ``` The unified runner forwards user-controlled URLs into both affected paths: ```python if is_wechat_url(args.url): steps.append("wechat-first") code, payload = run_json(FETCH_WECHAT, args.url, timeout=max(args.timeout, 30), max_chars=args.max_chars, cookie=args.cookie) if not is_good_enough(payload): steps.append("wechat-fallback-general") code, payload = run_json(FETCH_PAGE, args.url, timeout=args.timeout, max_chars=args.max_chars) if not is_good_enough(payload): steps.append("wechat-fallback-browser") code, payload = run_json(RENDER_PAGE, args.url, timeout=0, max_chars=args.max_chars, wait_ms=args.wait_ms) else: steps.append("general-first") code, payload = run_json(FETCH_PAGE, ar ...[truncated 2662 chars]- Remediation
View remediation
