Skip to content

fix(security): resolve CodeQL SSRF, ReDoS, sensitive logging, and weak hashing alerts - #25

Merged
spelech merged 1 commit into
mainfrom
fix/codeql-targeted-security-alerts
Sep 27, 2026
Merged

spelech merged 1 commit into
mainfrom
fix/codeql-targeted-security-alerts

Conversation

@spelech

@spelech spelech commented Sep 27, 2026

Copy link
Copy Markdown
Owner

Summary

This PR addresses 8 standalone Critical and High severity CodeQL alerts identified across the repository:

  1. py/full-ssrf (Alert #42 - Critical)

    • Added strict scheme validation (http, https) and cloud metadata endpoint blocking (169.254.169.254, metadata.google.internal) in app/services/litellm_service.py and app/api/routers/settings.py.
    • Reconstructed endpoints safely using urllib.parse.urlunsplit.
    • Added unit tests in tests/test_litellm_service.py for SSRF rejection.
  2. py/polynomial-redos (Alerts #43 & #44 - High)

    • Replaced ambiguous template literal regex with r'$\{([^{}]+)\}' in app/services/chunking/api_route_extractor.py.
    • Replaced backtracking regex folder matching with deterministic string splitting for Next.js App Router routes.
  3. js/incomplete-url-substring-sanitization (Alert #95 - High)

    • Parsed repository URL hostname via new URL(u).hostname and strictly checked domain boundaries in frontend/src/SearchInspector.tsx.
  4. py/clear-text-logging-sensitive-data (Alerts [Feature] AST-Based Call Graph Traversal & Relationship Tracing (trace_path MCP Tool) #1, [Feature] API Route Discovery & Cross-Service Endpoint Linking (find_routes & find_api_callers MCP Tools) #2, [Feature] Architecture Overview Synthesis & Architecture Decision Records (get_architecture & manage_adr MCP Tools) #3 - High)

    • Removed key prefix strings from informational logging in app/services/auth/key_service.py, keeping only non-sensitive identifiers (id, name, role).
  5. py/weak-sensitive-data-hashing (Alert #41 - High)

    • Upgraded API key hashing in app/services/auth/key_service.py from unhardened SHA-256 to salted PBKDF2-HMAC-SHA256 (hashlib.pbkdf2_hmac).

Verification

  • Pytest backend suite: 524 passing.
  • Vitest frontend suite: 291 passing.
  • Oxlint: 0 errors.

…k hashing alerts

- py/full-ssrf (#42): validate URL scheme, block restricted metadata hosts, and reconstruct safe endpoints with urlunsplit in litellm_service and settings router
- py/polynomial-redos (#43, #44): optimize template literal regex and switch Next.js route path extraction to deterministic component splitting in api_route_extractor
- js/incomplete-url-substring-sanitization (#95): parse hostname via new URL and verify domain boundaries in SearchInspector.tsx
- py/clear-text-logging-sensitive-data (#1, #2, #3): sanitize logging in key_service by eliminating key prefix strings from log messages
- py/weak-sensitive-data-hashing (#41): use PBKDF2-HMAC-SHA256 with salt for API key hashing in key_service
- sync test counts in REQUIREMENTS.md
@spelech
spelech merged commit b1e98f4 into main Sep 27, 2026
15 checks passed
@spelech
spelech deleted the fix/codeql-targeted-security-alerts branch September 27, 2026 11:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant