[Security] Six confirmed vulnerabilities remain in latest main
メンテナーはふだん 1 日以内に返信
まだ誰も着手していません。
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 25/100
- issue の種類
- バグ
- 明瞭さ
- おおむね明確
- 活発さ
- 活発
- 技術スタック
- typescript
調査の方向性
Review the six reported findings in src/utils/image.ts, src/commands/speech/synthesize.ts, src/files/download.ts, src/config/loader.ts, src/update/self-update.ts, and src/client/endpoints.ts. Start by comparing these files with the referenced audited commit and reproduce the stated behavior using the reporter's private PoCs when maintainers provide a private channel. Done means the six vulnerabilities are remediated and focused regression tests cover them.
索引モデルが issue の本文から書いたものです。
説明
Hello maintainers,
I am reporting six security findings that remain in the latest upstream main commit 06e47c70b76f419196678367dae62acca4c94076 (September 29, 2026). I compared the affected source files with the previously audited commit 33453cf123927f41c00e1935450e504d8a630763; all seven affected files are unchanged, so the original PoCs remain applicable.
The findings are:
-
Vision image SSRF and excessive buffering:
src/utils/image.tsfetches arbitrary HTTP(S) image URLs with the CLI's network privileges and buffers the complete response before applying the nominal size limit. A caller who can influence the image URL may reach local/private services and cause excessive memory use. -
Speech subtitle SSRF:
src/commands/speech/synthesize.tsfetches the API-providedsubtitle_fileURL directly. A malicious or compromised response can make the CLI contact local or private network services. -
Media download SSRF:
src/files/download.tsaccepts API-provided download URLs without rejecting local/private destinations, allowing an attacker-influenced response to make the CLI fetch and save unintended data. -
Config temporary-file symlink overwrite:
src/config/loader.tsuses a predictableconfig.json.tmppath. A local attacker able to plant a symlink can redirect credential/config data into another writable file. -
Self-update temporary-file symlink overwrite:
src/update/self-update.tsuses a predictable/tmp/mmx-update-<timestamp>path and normal write semantics. A local attacker can redirect update contents into another writable file. -
Authenticated query-parameter injection:
src/client/endpoints.tsinterpolates task/file identifiers into URLs without encoding. A crafted identifier can add parameters to a credentialed request and change how the server interprets it.
The first three findings are network-request issues. The next two require local access to manipulate temporary files. The sixth requires an attacker-influenced or compromised identifier source. The local PoCs reproduced the behavior against clean upstream code using only loopback mock servers and temporary files. No production internal service, metadata endpoint, paid generation, upload, destructive request, API key, or bearer token is included here.
Proposed fixes and focused regression tests are available in a private local worktree. GitHub private vulnerability reporting is disabled for this repository, and issue #265 requested a private channel but has received no response. Please acknowledge this report, route it to the CLI/security maintainers, and provide a private channel for the complete PoCs and remediation discussion. Please also confirm whether MiniMax-AI/cli is in scope for a security reward or bounty.
I will keep the detailed exploit material private while waiting for your instructions.
Reporter: Jonathan Shi (x4evexnol)
- 主要言語
- TypeScript
- スター
- 2.2k
- フォーク
- 185
- 平均マージ
- 9時間 55分
- マージ済み PR(30日)
- 4
環境構築
このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
MiniMax-AI/cli のほかの issue
-
[Bug] 未登录时 mmx help 被认证检查拦截,无法查看公开文档链接再び着手できるかも このイシューのプルリクエストはマージされずにクローズされました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 84/100
MiniMax-AI/cli#259 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
[Bug] --no-color 未去除请求状态栏的 ANSI 颜色再び着手できるかも このイシューのプルリクエストはマージされずにクローズされました。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
MiniMax-AI/cli#258 ·
メンテナーはふだん 1 日以内に返信
-
/compact commandオープン
難易度 5/5 1週間以上 初心者へのやさしさ 25/100
MiniMax-AI/cli#275 ·
メンテナーはふだん 1 日以内に返信
-
難易度 5/5 1週間以上 初心者へのやさしさ 25/100
MiniMax-AI/cli#260 ·
メンテナーはふだん 1 日以内に返信
-
難易度 3/5 1〜2日 初心者へのやさしさ 76/100
MiniMax-AI/cli#257 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
似ている issue
-
[Bug] The shared instance selector's placeholder and no-match text ignore the display language対応中かも このイシューにリンクされたプルリクエストがオープン中、またはマージ済みです。 オープン
難易度 2/5 1〜3時間 初心者へのやさしさ 90/100
apache/rocketmq-dashboard#5561 ·
メンテナーはふだん 3 日以内に返信
-
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
CopilotKit/OpenDots#69 ·
メンテナーはふだん 1 日以内に返信
-
sendDefaultPii is reported as deprecated on ReactNativeOptions although dataCollection is hiddenオープンBug React-Native Waiting for: Product Owner
難易度 2/5 1〜3時間 初心者へのやさしさ 85/100
getsentry/sentry-react-native#6830 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
OSCI'26
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
GauravKarakoti/SecureFlow#1215 ·
メンテナーはふだん 1 日以内に返信
-
[quality] bundle e2e never drives plain /close or the /milestone refusals through dist/index.js対応中かも @hivecommons-hive が今日担当しました。 オープンagent/quality hive/covered-by-pr hive/hosted-available-lke648397-260827-5q9t kind/cleanup quality testing
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
cncf/prow-github-actions#295 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信