T09 · Insecure Skill Coding Practices
- Location
scripts/feishu_media.py:89- Finding
Predictable Media Conversion Paths Allow Local File Clobbering
- Content
View full analysis
0 ``` ```python def send_audio(filepath, open_id=None, token=None, **kwargs): """Send audio as native voice bubble. Auto-converts to opus, always includes duration.""" token = token or get_token(kwargs.get('app_id'), kwargs.get('app_secret')) ffmpeg = kwargs.get('ffmpeg') ffprobe = kwargs.get('ffprobe') # Convert to opus if needed if not filepath.lower().endswith('.opus'): opus_path = os.path.splitext(filepath)[0] + '.opus' if not _to_opus(filepath, opus_path, ffmpeg): return {'code': -1, 'msg': 'Failed to convert to opus'} filepath = opus_path duration = _get_duration_ms(filepath, ffprobe) or 0 r = _multipart_upload(UPLOAD_API, {'file_type': 'opus', 'file_name': os.path.basename(filepath), 'duration': str(duration)}, ('file', filepath), token) if r['code'] != 0: return r return _send_msg(token, open_id or DEFAULT_OPEN_ID, 'audio', {'file_key': r['data']['file_key']}) def send_video(filepath, cover_image=None, open_id=None, token=None, **kwargs): """Send video as inline player. Auto-applies faststart, always includes duration.""" token = token or get_token(kwargs.get('app_id'), kwargs.get('app_ ...[truncated 3211 chars]- Remediation
View remediation
