Unauthenticated local-path APIs disclose arbitrary server files
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 35/100
Direzione di ricerca
Start with api/repository.py and api/services/codemap.py, then trace the public /codemap/file, /local_repo/structure, and /repo/prepare routes. Verify how repo_url becomes save_path and how containment is checked for local paths. Done means local paths are restricted to an operator-owned allowlisted root before file reading, structure access, or indexing; the issue notes that a fix is included in #594.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Affected versions: confirmed on main at commit d92819a9 (the project publishes no tagged release).
Summary
Multiple public routes (/codemap/file, /local_repo/structure, /repo/prepare) accept a caller-chosen local filesystem root via repo_url. Repo.is_local treats any value that isn't an http(s)/ftp URL with a host as a trusted local path, and Repo.save_path returned it unchanged with no containment. Selecting repo_url=/ makes any server-readable file reachable: /codemap/file returns its content directly, and /repo/prepare's indexer reads and embeds the whole tree.
Details
# api/repository.py
@property
def is_local(self) -> bool:
return not _path_is_url(self.repo_url)
@property
def save_path(self) -> str:
if self.is_local:
return self.repo_url # no allowlist at all
return os.path.join(self.root_path, self.name)
# api/services/codemap.py
def read_repo_file(repo_url, repo_type, file_path):
repo_dir = os.path.realpath(Repo(repo_url=repo_url, repo_type=repo_type).save_path)
target = os.path.realpath(os.path.join(repo_dir, file_path))
if os.path.commonpath([repo_dir, target]) != repo_dir:
raise ValueError(...)
...
Selecting repo_url=/ makes repo_dir resolve to /, so the containment check against repo_dir is a no-op: every absolute path is "within" /.
POC
(available upon request)
Impact
Any unauthenticated caller who can reach the API can read arbitrary server-readable files via GET /codemap/file?repo_url=/&file_path=<any absolute path minus the leading slash>, or have the RAG indexer embed and persist an entire arbitrary directory tree via /repo/prepare.
Suggested fix: require a local repository path to resolve within an operator-owned allowlisted root before any file/structure/indexing operation uses it. A fix is included in the linked PR.
Fix: #594
- Lingua principale
- Python
- Stelle
- 18.1k
- Fork
- 2k
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di AsyncFuncAI/deepwiki-open
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
AsyncFuncAI/deepwiki-open#608 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
AsyncFuncAI/deepwiki-open#602 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
AsyncFuncAI/deepwiki-open#589 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
AsyncFuncAI/deepwiki-open#539 · 1 commento ·
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 45/100
AsyncFuncAI/deepwiki-open#610 ·
Tutte le issue di AsyncFuncAI/deepwiki-open
Issue simili
-
docs(types): update the collection binding note now that typed collections shipped in pycubrid 1.9.0Apertadocumentation priority: low size: S
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
cubrid-lab/sqlalchemy-cubrid#768 ·
I maintainer di solito rispondono entro 1 giorno
-
bug help wanted
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
I maintainer di solito rispondono entro 1 giorno
-
Broken link in index.rstApertadocumentation
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 65/100
ansys/pydpf-core#3547 ·
I maintainer di solito rispondono entro 1 giorno
-
core
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
vectorize-io/hindsight#5457 ·
I maintainer di solito rispondono entro 1 giorno
-
[Bug]: LangChain drops OpenAI Responses text blocks from session recordingForse già presa @ktz03 l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
volcengine/OpenViking#5806 ·
I maintainer di solito rispondono entro 1 giorno