T09 · Insecure Skill Coding Practices
- Location
scripts/design_sgrna.py:8- Finding
Unbounded External HTTP Request May Cause Resource Exhaustion
- Content
View full analysis
Vulnerability Details
File Location:
scripts/design_sgrna.py:8-14
Vulnerability Type: Unbounded external HTTP request
Risk Level: LowVulnerable Code
python def fetch_ncbi_sequence(accession, start=None, end=None): print(f"Fetching sequence for {accession}...") url = f"https://eutils.ncbi.nlm.nih.gov/entrez/eutils/efetch.fcgi?db=nuccore&id={accession}&rettype=fasta&retmode=text" if start and end: url += f"&seq_start={start}&seq_stop={end}" response = requests.get(url) if response.status_code == 200: lines = response.text.split('\n') return "".join(lines[1:]) return NoneTechnical Analysis
The NCBI request is made without connection or read timeouts. Consequently, a stalled endpoint or network connection can block the process indefinitely. The response is also loaded and decoded in full through
response.text, split into another in-memory representation, and concatenated before downstream sequence processing. No maximum response or sequence length is enforced.User-controlled accession and coordinate values are interpolated into the query string rather than supplied through the request library's parameter-encoding interface. Although the destination is fixed to the official NCBI HTTPS host and no arbitrary-host request was identified, explicit input validation and safe query encoding are still absent.
Attack Path
- An attacker or untrusted caller supplies an accession or coordinate range that causes retrieval of an excessively large sequence.
- The script sends the request to the fixed NCBI endpoint without a timeout.
- A slow response can hold the process indefinitely, while a large response is loaded fully into memory.
- The code creates additional copies during text decoding, line splitting, concatenation, reverse-complement generation, and candidate scanning.
- The process may experience excessive memory con ...[truncated 633 chars]
- Remediation
View remediation
Remediation Suggestions
- Apply explicit connection and read timeouts, for example
timeout=(5, 30). - Pass query values through the
paramsargument rather than manual string interpolation. - Validate accession identifiers against an allowlisted format and reject malformed or excessively long values.
- Validate coordinates as positive integers, require
start <= end, and impose a maximum permitted range. - Use streaming response handling and stop reading after a configured byte limit.
- Enforce a maximum decoded sequence length before reverse-complement generation and PAM scanning.
- Call
response.raise_for_status()and handlerequests.Timeout,requests.ConnectionError, and related exceptions explicitly. - Avoid unnecessary full-size intermediate copies where practical.
- Apply explicit connection and read timeouts, for example
