Skip to content

fix(security): resolve final 24 CodeQL alerts for path injection and stack trace exposure - #28

Merged
spelech merged 1 commit into
mainfrom
fix/codeql-remaining-alerts
Sep 27, 2026
Merged

spelech merged 1 commit into
mainfrom
fix/codeql-remaining-alerts

Conversation

@spelech

@spelech spelech commented Sep 27, 2026

Copy link
Copy Markdown
Owner

Summary

Remediates the final 24 open CodeQL security alerts:

  1. py/stack-trace-exposure (6 alerts):

    • Sanitized exception returns in app/services/git_manager.py (rate limit check).
    • Sanitized error returns in app/services/vector_store/manager.py (get_vector_store_config, switch_vector_store, test_connection).
    • Sanitized exception returns in Chroma, Qdrant, and PgVector store health_check implementations.
  2. py/path-injection (18 alerts):

    • app/api/routers/repositories.py: Added startswith and commonpath root containment validations before os.path.exists and os.scandir in api_add_path and api_browse_dir.
    • app/api/routers/settings.py: Added path validation on storage_path in api_test_vector_store and api_switch_vector_store.
    • app/services/file_reader.py: Relocated root prefix checks prior to os.path.lexists calls and added barrier checks in is_binary_file and read_file.
    • app/services/summarizer.py: Added root prefix validation before fallback disk file reads.
    • app/services/vector_store/chroma_store.py & qdrant_store.py: Added root validation before os.makedirs on embedded storage paths.

Verification

  • Full test suite passed: 524 passed, 2 skipped in 32.98s.

…stack trace exposure

- Sanitize exception responses and rate limit errors in git_manager, vector_store manager, and vector store adapters (chroma, qdrant, pgvector).
- Enforce canonical root-prefix and commonpath sanitization before file system operations across file_reader, summarizer, repositories router, and vector stores.
- Update unit tests to verify error handling without expecting exposed internal exceptions.
@spelech
spelech merged commit 891a7a0 into main Sep 27, 2026
11 checks passed
@spelech
spelech deleted the fix/codeql-remaining-alerts branch September 27, 2026 11:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant