T09 · Insecure Skill Coding Practices
- Location
scripts/semantic_scholar_cli.py:253- Finding
Semantic Scholar session cookies can be transmitted to arbitrary origins
- Content
View full analysis
dict[str, str]: headers = { "User-Agent": DEFAULT_USER_AGENT, "Accept": accept, } if bundle is not None: headers["Cookie"] = cookie_header_from_bundle(bundle) user_agent = str(bundle.get("userAgent", "")).strip() if user_agent: headers["User-Agent"] = user_agent if referer: headers["Referer"] = referer if content_type: headers["Content-Type"] = content_type return headers ``` ```python # scripts/ss_store.py:278-291 def fetch_html( url: str, bundle: dict[str, Any], *, referer: str | None = None, timeout: int = DEFAULT_TIMEOUT, ) -> str: response = request( url, headers=build_auth_headers(bundle, accept="text/html,application/xhtml+xml", referer=referer), timeout=timeout, ) require_ok(response, f"Fetching HTML from {url}") return response.text ``` ### Technical Analysis The `ssr-dump` and `feed-crawl` commands accept `--page-url` without validating its scheme, hostname, port, or or ...[truncated 2926 chars]- Remediation
View remediation
