T05 · Unauthorized Access and Privilege Escalation
- Location
src/api/server.py:19- Finding
Unauthenticated API Exposes Credential-Backed Dynamic Tool Execution
- Content
View full analysis
TradingAgent: """Get or create an agent for a session.""" if session_id not in agents: agents[session_id] = TradingAgent() return agents[session_id] ``` ```python # src/api/server.py app.add_middleware( CORSMiddleware, allow_origins=["*"], allow_credentials=True, allow_methods=["*"], allow_headers=["*"], ) ``` ```python # src/api/server.py @app.post("/api/chat", response_model=ChatResponse) async def chat(request: ChatRequest): """Send a message to the trading agent.""" try: agent = get_or_create_agent(request.session_id) # Clear history for each chat to avoid accumulation issues agent.clear_history() response = await agent.chat(request.message) return ChatResponse(response=response, session_id=request.session_id) except Exception as e: raise HTTPException(status_code=500, detail=str(e)) ``` ```python # src/api/server.py if __name__ == "__main__": import uvicorn uvicorn.run(app, host="0.0.0.0", port=8000) ``` ```python # src/agents/trading_agent.py async def get_tools(self) -> list: """Get dynamic tools from UnifAI.""" return await self.tools.get_tools(dynamic_tools=True) async def execute_tool_calls(self, tool_calls) -> list: """Execute tool calls and return results.""" return await self.tools.call_tools(tool_calls) ``` ```python # src/agents/trading_agent.py available_tools = await self.get_tools() # Allow multiple rounds of tool calls max_iterations = 5 for _ in range(max_iterations): response = await litellm.acompletion( model=self.model, ...[truncated 3196 chars]- Remediation
View remediation
