cesto-creator-toolkit
Audited by Socket on Sep 15, 2026
2 alerts found:
AnomalySecurityNo clear malicious behavior or exfiltration is present. The code implements local session-token storage, but its XOR/Base85 protection is cryptographically weak and should be replaced with authenticated encryption or a platform credential store. File writes should use safer atomic and symlink-resistant handling. The fragment also appears to contain a missing closing parenthesis at the end.
The code appears intended to be an authenticated API request wrapper, not overt malware. However, the URL allowlist is vulnerable to hostname-prefix bypasses. An attacker able to control the URL argument can cause the stored bearer token, and potentially request data, to be sent to an unauthorized domain such as backend.cesto.co.evil. The check should parse the URL and require an exact hostname and HTTPS scheme, with appropriate port restrictions. The issue is a significant credential-exfiltration risk in contexts where untrusted callers can invoke the script.