[Security] Six confirmed vulnerabilities remain in latest main
维护者通常 1 天内回复
评估
- 难度
- 5/5
- 预计耗时
- 一周以上
- 新手友好度
- 25/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 活跃
- 技术栈
- typescript
调研方向
Review the six reported findings in src/utils/image.ts, src/commands/speech/synthesize.ts, src/files/download.ts, src/config/loader.ts, src/update/self-update.ts, and src/client/endpoints.ts. Start by comparing these files with the referenced audited commit and reproduce the stated behavior using the reporter's private PoCs when maintainers provide a private channel. Done means the six vulnerabilities are remediated and focused regression tests cover them.
由索引模型根据 Issue 内容生成。
描述
Hello maintainers,
I am reporting six security findings that remain in the latest upstream main commit 06e47c70b76f419196678367dae62acca4c94076 (September 29, 2026). I compared the affected source files with the previously audited commit 33453cf123927f41c00e1935450e504d8a630763; all seven affected files are unchanged, so the original PoCs remain applicable.
The findings are:
-
Vision image SSRF and excessive buffering:
src/utils/image.tsfetches arbitrary HTTP(S) image URLs with the CLI's network privileges and buffers the complete response before applying the nominal size limit. A caller who can influence the image URL may reach local/private services and cause excessive memory use. -
Speech subtitle SSRF:
src/commands/speech/synthesize.tsfetches the API-providedsubtitle_fileURL directly. A malicious or compromised response can make the CLI contact local or private network services. -
Media download SSRF:
src/files/download.tsaccepts API-provided download URLs without rejecting local/private destinations, allowing an attacker-influenced response to make the CLI fetch and save unintended data. -
Config temporary-file symlink overwrite:
src/config/loader.tsuses a predictableconfig.json.tmppath. A local attacker able to plant a symlink can redirect credential/config data into another writable file. -
Self-update temporary-file symlink overwrite:
src/update/self-update.tsuses a predictable/tmp/mmx-update-<timestamp>path and normal write semantics. A local attacker can redirect update contents into another writable file. -
Authenticated query-parameter injection:
src/client/endpoints.tsinterpolates task/file identifiers into URLs without encoding. A crafted identifier can add parameters to a credentialed request and change how the server interprets it.
The first three findings are network-request issues. The next two require local access to manipulate temporary files. The sixth requires an attacker-influenced or compromised identifier source. The local PoCs reproduced the behavior against clean upstream code using only loopback mock servers and temporary files. No production internal service, metadata endpoint, paid generation, upload, destructive request, API key, or bearer token is included here.
Proposed fixes and focused regression tests are available in a private local worktree. GitHub private vulnerability reporting is disabled for this repository, and issue #265 requested a private channel but has received no response. Please acknowledge this report, route it to the CLI/security maintainers, and provide a private channel for the complete PoCs and remediation discussion. Please also confirm whether MiniMax-AI/cli is in scope for a security reward or bounty.
I will keep the detailed exploit material private while waiting for your instructions.
Reporter: Jonathan Shi (x4evexnol)
- 主要语言
- TypeScript
- 星标
- 2.2k
- 派生
- 187
- 平均合并
- 9 小时 55 分钟
- 30 天内合并 PR
- 4
环境准备
这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
MiniMax-AI/cli 的其他 Issue
-
[Bug] 未登录时 mmx help 被认证检查拦截,无法查看公开文档链接可能重新可做 关联的 PR 已关闭且未合并。 未关闭
难度 2/5 1-3 小时 新手友好度 84/100
MiniMax-AI/cli#259 · 1 条评论 ·
维护者通常 1 天内回复
-
[Bug] --no-color 未去除请求状态栏的 ANSI 颜色可能重新可做 关联的 PR 已关闭且未合并。 未关闭
难度 2/5 1-3 小时 新手友好度 88/100
MiniMax-AI/cli#258 ·
维护者通常 1 天内回复
-
/compact command未关闭
难度 5/5 一周以上 新手友好度 25/100
MiniMax-AI/cli#275 ·
维护者通常 1 天内回复
-
难度 5/5 一周以上 新手友好度 25/100
MiniMax-AI/cli#260 ·
维护者通常 1 天内回复
-
难度 3/5 1-2 天 新手友好度 76/100
MiniMax-AI/cli#257 · 1 条评论 ·
维护者通常 1 天内回复
相似的 Issue
-
area/dashboard kind/bug QA/dev-automation
难度 2/5 1-3 小时 新手友好度 65/100
rancher/dashboard#19379 · 2 条评论 ·
维护者通常 5 天内回复
-
perf(core): getComments() runs the approved count and the comment list as two sequential queries未关闭area/core bot:bug bot:working
难度 2/5 1-3 小时 新手友好度 76/100
emdash-cms/emdash#3905 · 2 条评论 ·
维护者通常 1 天内回复
-
community first-timers-only good first issue hacktoberfest help wanted low hanging fruit up-for-grabs
难度 1/5 1 小时以内 新手友好度 90/100
lingdojo/kana-dojo#31728 · 1 条评论 · 5 个 reaction ·
维护者通常 1 天内回复
-
selective-claw: freshTailTurns=0 keeps ALL turns verbatim and summarizes none (slice(-0) === slice(0))可能已有人在做 @zjncs 今天认领。 未关闭component:tokenless
难度 2/5 1-3 小时 新手友好度 80/100
agentic-os-org/ANOLISA#6112 · 1 条评论 ·
维护者通常 1 天内回复
-
bug needs triage
难度 2/5 1-3 小时 新手友好度 75/100
rjsf-team/react-jsonschema-form#5439 ·
维护者通常 1 天内回复