T05 · Unauthorized Access and Privilege Escalation
- Location
SKILL.md:76- Finding
Local HTTP Server Exposes the Entire Downloads Directory
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 76
Vulnerability Type: Excessively broad local file exposure
Risk Level: MediumVulnerable Code:
bash screen -dmS smartlink_http_8767 bash -lc 'cd "/Users/tangmingying/Downloads" && python3 -m http.server 8767 --bind 127.0.0.1 > /tmp/smartlink_http_8767.log 2>&1'Technical Analysis
The command starts a Python HTTP server with the user's entire Downloads directory as its document root. Although the service is bound to the loopback interface, any process running in the same host or network namespace can request files from that directory.
The intended operation only requires access to the SmartLink workbench and its assets. Serving the complete Downloads directory violates least privilege and may expose unrelated documents, exported credentials, archives, reports, or other sensitive files. Python's basic HTTP server does not provide authentication or per-file authorization.
Attack Path
- A sensitive or unrelated file exists under
/Users/tangmingying/Downloads. - The Agent follows the Skill instructions and starts the HTTP server.
- A malicious or compromised local process enumerates
http://127.0.0.1:8767/or requests a known filename. - The server returns the file without authentication.
- The local process reads or further distributes the exposed content.
Impact Assessment
Exploitation can disclose any file readable by the service account and located beneath the Downloads directory. It does not directly grant privileges beyond the account running the server, but it bypasses the intended file-level access boundary by making unrelated files available over an unauthenticated local endpoint. The scope is limited to files served from the selected document root and the lifetime of the HTTP server.
- A sensitive or unrelated file exists under
- Remediation
View remediation
Remediation Suggestions
-
Create a dedicated directory containing only the workbench HTML and required static assets.
-
Start the HTTP server with that dedicated directory as its document root, for example:
bash python3 -m http.server 8767 --bind 127.0.0.1 --directory "/path/to/smartlink-preview" -
Apply restrictive permissions to the preview directory and its contents.
-
Avoid copying confidential or unrelated files into the served directory.
-
Shut down the server when previewing is complete.
-
If untrusted local processes are within the threat model, use a server that supports authentication and explicit path allowlisting.
-
