T05 · Unauthorized Access and Privilege Escalation
- Location
references/transcribe_server.py:407- Finding
Unauthenticated Network API Permits Processing of Arbitrary Local Audio Files
- Content
View full analysis
web.Application: app = web.Application(middlewares=[cors_middleware]) app.router.add_get("/api/health", health_handler) app.router.add_get("/api/models", models_handler) app.router.add_post("/api/upload", upload_handler) app.router.add_post("/api/transcribe", transcribe_handler) app.router.add_get("/api/tasks/{task_id}", task_status_handler) app.router.add_post("/api/tasks/{task_id}/cancel", cancel_task_handler) app.router.add_post("/api/translate", translate_handler) return app ``` ```python web.run_app(create_app(), host="0.0.0.0", port=port, print=None) ``` ### Technical Analysis The backend listens on every available network interface and does not authenticate any API route. The transcription endpoint accepts a client-control ...[truncated 2190 chars]- Remediation
View remediation
