T09 · Insecure Skill Coding Practices
- Location
scripts/create_task.py:37- Finding
Access Token May Be Disclosed Through Cross-Origin HTTP Redirects
- Content
View full analysis
Vulnerability Details
File Location:
scripts/create_task.py, lines 37-41
Vulnerability Type: Sensitive credential exposure through unsafe redirect handling
Risk Level: Mediumpython headers = {"Content-Type": "application/json"} if args.access_token: headers["access_token"] = args.access_token req = urllib.request.Request(url=url, data=data, headers=headers, method="POST") try: with urllib.request.urlopen(req, timeout=30) as resp:Technical Analysis
The script places the user-provided access token in a custom HTTP header and sends the request using
urllib.request.urlopen. This function follows supported HTTP redirects by default, while the code does not validate redirect destinations or explicitly prevent the sensitive custom header from being forwarded.Consequently, a compromised or misconfigured API server, reverse proxy, CDN, or DNS/TLS-controlled endpoint could return a redirect to another origin. Depending on the runtime's redirect behavior, the custom
access_tokenheader may be copied into the redirected request. Unlike secure clients that explicitly remove authorization credentials on cross-origin redirects, this implementation establishes no origin-boundary protection for the custom credential.Attack Path
- A user invokes the script with a valid
--access-token. - The script adds that value to the
access_tokenrequest header. - The request is sent to
https://softcraft.cloud/api/skill/tasks/. - A compromised or misconfigured API endpoint, reverse proxy, or CDN responds with a supported redirect to an attacker-controlled HTTPS origin.
- The default redirect handler follows the redirect without application-level validation of the destination.
- If the custom header is retained by the active Python runtime, the attacker-controlled server receives and records the access token.
- The attacker reuses the captured token against any service operations for ...[truncated 724 chars]
- A user invokes the script with a valid
- Remediation
View remediation
Remediation Suggestions
- Disable automatic redirects for requests carrying credentials, or use a custom redirect handler that inspects every redirect before following it.
- Permit redirects only when the destination uses HTTPS and its normalized hostname is exactly
softcraft.cloud. Validate the effective port and reject user-information components, malformed hostnames, and hostname-suffix tricks. - Remove the
access_tokenheader whenever the scheme, hostname, or port changes. Do not rely solely on library-version-specific redirect behavior. - Prefer the standard
Authorization: Bearer ...scheme where supported, while still enforcing explicit cross-origin credential stripping. - Use narrowly scoped, short-lived tokens and implement server-side revocation and expiration.
- Add automated tests covering same-origin redirects, cross-origin redirects, HTTPS-to-HTTP redirects, redirect loops, and attempted credential forwarding.
- Consider rejecting redirects entirely for this fixed API endpoint because a normal task-creation request should not require redirection.
