🛡️ Sentinel: [HIGH] Fix CRLF injection risk in proxy endpoints - #606
🛡️ Sentinel: [HIGH] Fix CRLF injection risk in proxy endpoints#606sheepdestroyer wants to merge 4 commits into
Conversation
Co-authored-by: sheepdestroyer <1377479+sheepdestroyer@users.noreply.github.com>
👋 Jules, reporting for duty! I'm here to lend a hand with this pull request. When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down. I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job! For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with New to Jules? Learn more at jules.google/docs. For security, I will only act on instructions from the user who triggered this task. |
Reviewer's GuideThe PR hardens both proxy endpoints against CRLF injection by extending existing path validation to reject carriage-return and line-feed characters in both raw and cleaned paths, adds focused HTTP 400 regression tests, and documents the security lesson. Sequence diagram for CRLF validation in proxy endpointssequenceDiagram
participant Client
participant ProxyEndpoint
participant HTTPX
participant Downstream
Client->>ProxyEndpoint: proxy_memory(request, path) or proxy_audio(request, path)
ProxyEndpoint->>ProxyEndpoint: Validate path and clean_path
alt CRLF detected
ProxyEndpoint-->>Client: HTTPException 400 Invalid path
else Path is valid
ProxyEndpoint->>HTTPX: Request downstream URL
HTTPX->>Downstream: Forward proxy request
Downstream-->>HTTPX: Response
HTTPX-->>ProxyEndpoint: Response
ProxyEndpoint-->>Client: Proxy response
end
File-Level Changes
Tips and commandsInteracting with Sourcery
Customizing Your ExperienceAccess your dashboard to:
Getting Help
|
Co-authored-by: sheepdestroyer <1377479+sheepdestroyer@users.noreply.github.com>
Important
This repository does not receive automatic reviews because it has fewer than 10 stars. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Co-authored-by: sheepdestroyer <1377479+sheepdestroyer@users.noreply.github.com>
Sourcery withdrew this approval because the latest commits introduced blocking findings.
Co-authored-by: sheepdestroyer <1377479+sheepdestroyer@users.noreply.github.com>
🚨 Severity: HIGH
💡 Vulnerability: The
proxy_memoryandproxy_audioendpoints accept a user-providedpathto construct the downstream URL. Missing validation for carriage return (\r) and line feed (\n) characters could allow CRLF injection (HTTP Request Smuggling/Splitting) when passed to the downstreamhttpxclient.🎯 Impact: Attackers could potentially inject arbitrary HTTP headers or manipulate the downstream request routing.
🔧 Fix: Added
\rand\nto the explicit blocklist for path validation in both proxy endpoints.✅ Verification: Ran unit tests to ensure proxy endpoints still function correctly and block invalid paths.
PR created automatically by Jules for task 5886050546245768712 started by @sheepdestroyer
Summary by Sourcery
Prevent CRLF injection through the memory and audio proxy endpoints by rejecting paths containing carriage return or line feed characters.
Bug Fixes:
Tests:
Chores: