other
- Location
scripts/xhs/login.py:149- Finding
Live login QR code is disclosed to an external service
- Content
View full analysis
str | None: import http.client boundary = "----XhsQrBoundary" body = ( f"--{boundary}\r\n" f'Content-Disposition: form-data; name="file";' f' filename="qr.png"\r\n' f"Content-Type: image/png\r\n\r\n" ).encode() + png_bytes + f"\r\n--{boundary}--\r\n".encode() try: conn = http.client.HTTPSConnection( "api.qrserver.com", timeout=5 ) conn.request( "POST", "/v1/read-qr-code/", body=body, headers={ "Content-Type": ( f"multipart/form-data; boundary={boundary}" ), }, ) resp = conn.getresponse() if resp.status != 200: return None result = json.loads(resp.read().decode()) data = result[0]["symbol"][0].get("data") return data if data else None except Exception: return None def make_qrcode_url( png_bytes: bytes, ) -> tuple[str, str | None]: import base64 import urllib.parse qr_content = _decode_qr_content(png_bytes) if qr_content: image_url = ( "https://api.qrserver.com/v1/create-qr-code/" "?size=300x300&data=" + urllib.parse.quote(qr_content, safe="") ) return image_url, qr_content b64 = base64.b64encode(png_bytes).decode() return "data:image/png;base64," + b64, None ``` ### Technical Analysis The login workflow extracts a live Xiaohongshu QR image from the browser and sends the entire image to `api.qrserver.com` for decoding. This discloses an authentication artifact to a third party even though the QR image is already available locally and can be displayed ...[truncated 1377 chars]- Remediation
View remediation
