Hacktoberfest 2026:维护者为十月标记出来的 issue,仍然开放、适合新手。 浏览 Hacktoberfest issue

Unauthenticated local-path APIs disclose arbitrary server files

未关闭
#601 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
4/5
预计耗时
3-5 天
新手友好度
35/100
Issue 类型
缺陷
描述清晰度
描述清楚
活跃度
活跃
技术栈
python
领域
api, backend, security

调研方向

Start with api/repository.py and api/services/codemap.py, then trace the public /codemap/file, /local_repo/structure, and /repo/prepare routes. Verify how repo_url becomes save_path and how containment is checked for local paths. Done means local paths are restricted to an operator-owned allowlisted root before file reading, structure access, or indexing; the issue notes that a fix is included in #594.

由索引模型根据 Issue 内容生成。

描述

Affected versions: confirmed on main at commit d92819a9 (the project publishes no tagged release).

Summary

Multiple public routes (/codemap/file, /local_repo/structure, /repo/prepare) accept a caller-chosen local filesystem root via repo_url. Repo.is_local treats any value that isn't an http(s)/ftp URL with a host as a trusted local path, and Repo.save_path returned it unchanged with no containment. Selecting repo_url=/ makes any server-readable file reachable: /codemap/file returns its content directly, and /repo/prepare's indexer reads and embeds the whole tree.

Details

# api/repository.py
@property
def is_local(self) -> bool:
    return not _path_is_url(self.repo_url)

@property
def save_path(self) -> str:
    if self.is_local:
        return self.repo_url   # no allowlist at all
    return os.path.join(self.root_path, self.name)
# api/services/codemap.py
def read_repo_file(repo_url, repo_type, file_path):
    repo_dir = os.path.realpath(Repo(repo_url=repo_url, repo_type=repo_type).save_path)
    target = os.path.realpath(os.path.join(repo_dir, file_path))
    if os.path.commonpath([repo_dir, target]) != repo_dir:
        raise ValueError(...)
    ...

Selecting repo_url=/ makes repo_dir resolve to /, so the containment check against repo_dir is a no-op: every absolute path is "within" /.

POC

(available upon request)

Impact

Any unauthenticated caller who can reach the API can read arbitrary server-readable files via GET /codemap/file?repo_url=/&file_path=<any absolute path minus the leading slash>, or have the RAG indexer embed and persist an entire arbitrary directory tree via /repo/prepare.

Suggested fix: require a local repository path to resolve within an operator-owned allowlisted root before any file/structure/indexing operation uses it. A fix is included in the linked PR.

Fix: #594

主要语言
Python
星标
18.1k
派生
2k
PR 合并指标
30 天内没有已合并 PR

环境准备

这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

AsyncFuncAI/deepwiki-open 的其他 Issue

查看 AsyncFuncAI/deepwiki-open 的全部 Issue

相似的 Issue

更多 Python Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。