T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/cdp-proxy.mjs:261- Finding
Unauthenticated Local API Exposes Full Control of Authenticated Chrome Sessions
- Content
View full analysis
{ const parsed = new URL(req.url, `http://localhost:${PORT}`); const pathname = parsed.pathname; const q = Object.fromEntries(parsed.searchParams); res.setHeader('Content-Type', 'application/json; charset=utf-8'); try { // /health does not require a Chrome connection if (pathname === '/health') { const connected = ws && (ws.readyState === WS.OPEN || ws.readyState === 1); res.end(JSON.stringify({ status: 'ok', connected, sessions: sessions.size, chromePort })); return; } await connect(); ``` ```js // GET /targets - list all pages if (pathname === '/targets') { const resp = await sendCDP('Target.getTargets'); const pages = resp.result.targetInfos.filter(t => t.type === 'page'); res.end(JSON.stringify(pages, null, 2)); } ``` ```js // POST /eval?target=xxx - execute JavaScript else if (pathname === '/eval') { const sid = await ensureSession(q.target); const body = await readBody(req); const expr = body || q.expr || 'document.title'; const resp = await sendCDP('Runtime.evaluate', { expression: expr, returnByValue: true, awaitPromise: true, }, sid); if (resp.result?.result?.value !== undefined) { res.end(JSON.stringify({ value: resp.result.result.value })); } else if (resp.result?.exceptionDetails) { res.statusCode = 400; res.end(JSON.stringify({ error: resp.result.exceptionDetails.text })); } else { res.end(JSON.stringify(resp.result)); } } ``` ```js else if (pathname === '/setFiles') { const sid = await ensureSession(q.target); const body = JSON.parse(await readBody(req)); if (!body.selector || !body.files) { res.statusCode = 400; r ...[truncated 3437 chars]- Remediation
View remediation
