Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

[Security] Six confirmed vulnerabilities remain in latest main

Abierto
#273 1 comentario 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

@rahmaniramin550-ai ya está trabajando en esto.

Desde el 2/10/2026.

  • #274 de @rahmaniramin550-ai — abierto

Evaluación

Dificultad
5/5
Tiempo estimado
Más de una semana
Aptitud para principiantes
25/100
Tipo de issue
Error
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
typescript
Área
cli, security

Línea de trabajo

Review the six reported findings in src/utils/image.ts, src/commands/speech/synthesize.ts, src/files/download.ts, src/config/loader.ts, src/update/self-update.ts, and src/client/endpoints.ts. Start by comparing these files with the referenced audited commit and reproduce the stated behavior using the reporter's private PoCs when maintainers provide a private channel. Done means the six vulnerabilities are remediated and focused regression tests cover them.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

Hello maintainers,

I am reporting six security findings that remain in the latest upstream main commit 06e47c70b76f419196678367dae62acca4c94076 (September 29, 2026). I compared the affected source files with the previously audited commit 33453cf123927f41c00e1935450e504d8a630763; all seven affected files are unchanged, so the original PoCs remain applicable.

The findings are:

  1. Vision image SSRF and excessive buffering: src/utils/image.ts fetches arbitrary HTTP(S) image URLs with the CLI's network privileges and buffers the complete response before applying the nominal size limit. A caller who can influence the image URL may reach local/private services and cause excessive memory use.

  2. Speech subtitle SSRF: src/commands/speech/synthesize.ts fetches the API-provided subtitle_file URL directly. A malicious or compromised response can make the CLI contact local or private network services.

  3. Media download SSRF: src/files/download.ts accepts API-provided download URLs without rejecting local/private destinations, allowing an attacker-influenced response to make the CLI fetch and save unintended data.

  4. Config temporary-file symlink overwrite: src/config/loader.ts uses a predictable config.json.tmp path. A local attacker able to plant a symlink can redirect credential/config data into another writable file.

  5. Self-update temporary-file symlink overwrite: src/update/self-update.ts uses a predictable /tmp/mmx-update-<timestamp> path and normal write semantics. A local attacker can redirect update contents into another writable file.

  6. Authenticated query-parameter injection: src/client/endpoints.ts interpolates task/file identifiers into URLs without encoding. A crafted identifier can add parameters to a credentialed request and change how the server interprets it.

The first three findings are network-request issues. The next two require local access to manipulate temporary files. The sixth requires an attacker-influenced or compromised identifier source. The local PoCs reproduced the behavior against clean upstream code using only loopback mock servers and temporary files. No production internal service, metadata endpoint, paid generation, upload, destructive request, API key, or bearer token is included here.

Proposed fixes and focused regression tests are available in a private local worktree. GitHub private vulnerability reporting is disabled for this repository, and issue #265 requested a private channel but has received no response. Please acknowledge this report, route it to the CLI/security maintainers, and provide a private channel for the complete PoCs and remediation discussion. Please also confirm whether MiniMax-AI/cli is in scope for a security reward or bounty.

I will keep the detailed exploit material private while waiting for your instructions.

Reporter: Jonathan Shi (x4evexnol)

Lenguaje dominante
TypeScript
Estrellas
2.2k
Forks
187
Merge medio
9 h 55 min
PR fusionados (30 d)
4

Preparar el entorno

Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de MiniMax-AI/cli

Todos los issues de MiniMax-AI/cli

Issues similares

Más issues de TypeScript

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.