T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/parse.js:40- Finding
Unrestricted URL Navigation Enables Server-Side Request Forgery
- Content
View full analysis
{ const imgs = Array.from(document.querySelectorAll('img')); return imgs.map(img => img.dataset.src || img.dataset.lazySrc || img.src || '') .filter(src => src && src.startsWith('http') && !src.includes('track') && !src.includes('pixel')); }); for (const imgUrl of imgUrls) { try { const imgResponse = await page.goto(imgUrl, { timeout: 30000, waitUntil: 'domcontentloaded' }); if (imgResponse && imgResponse.ok()) { const buffer = await imgResponse.body(); // Skip images that are too small if (buffer.length < minImageSize) continue; let ext = '.jpg'; if (imgUrl.includes('.png')) ext = '.png'; else if (imgUrl.includes('.gif')) ext = '.gif'; else if (imgUrl.includes('.webp')) ext = '.webp'; result.images.push({ url: imgUrl, buffer, ext }); } } catch (imgErr) { // Failure of one image does not interrupt processing } } } ``` ### Technical Analysis `parsePage` accepts a caller-controlled URL and passes it directly to `page.goto` without validating its hostname, resolved IP address, port, or redirect destination. Although the skill documentation presents this as a parser for `dedao.cn` sharing links, the implementation does not enforce that restriction. The page can also control the image URLs placed in `imgUrls`. The only protocol-related check is `src.startsWith('http')`, which permits both HTTP and HTTPS requests to arbitrar ...[truncated 2293 chars]- Remediation
View remediation
