Skip to content

fix: block private/local URL fetches in getUrlContextItems - #13324

Open
gokay-ai wants to merge 4 commits into
continuedev:mainfrom
gokay-ai:fix/fetch-url-private-ip-ssrf-13310
Open

gokay-ai wants to merge 4 commits into
continuedev:mainfrom
gokay-ai:fix/fetch-url-private-ip-ssrf-13310

Conversation

@gokay-ai

Copy link
Copy Markdown

Description

getUrlContextItems / fetchUrlContent fetched arbitrary URLs with no private-IP check. This adds assertPublicHttpUrl (via the existing is-localhost-ip helper) so private, loopback, and link-local destinations are rejected before favicon or content fetch.

Fixes #13310

Testing

cd core
npx vitest run util/assertPublicUrl.vitest.ts context/providers/URLContextProvider.vitest.ts tools/implementations/fetchUrlContent.vitest.ts

All 10 tests passed locally.

Notes

  • Keeps the existing permission prompt path.
  • Initial URL host is checked; follow-up for redirect re-check / optional allowPrivateNetwork can be separate if useful.
  • I have read the CLA Document and I hereby sign the CLA

Reject http(s) URLs whose host resolves to a private, loopback, or
link-local address before favicon or content fetch runs, using the
existing is-localhost-ip helper. Keeps agent Read URL / fetchUrlContent
from SSRF-shaped egress to RFC1918 and cloud metadata addresses.

Fixes continuedev#13310

Signed-off-by: GokayAI <60583610+gokay-ai@users.noreply.github.com>
@gokay-ai
gokay-ai requested a review from a team as a code owner September 29, 2026 06:26
@gokay-ai
gokay-ai requested review from sestinj and a balanced review from Copilot and removed request for a team September 29, 2026 06:26

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@github-actions

github-actions Bot commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

All contributors have signed the CLA ✍️ ✅
Posted by the CLA Assistant Lite bot.

Signed-off-by: GokayAI <60583610+gokay-ai@users.noreply.github.com>
@gokay-ai

Copy link
Copy Markdown
Author

I have read the CLA Document and I hereby sign the CLA

Signed-off-by: GokayAI <60583610+gokay-ai@users.noreply.github.com>
Signed-off-by: GokayAI <60583610+gokay-ai@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

fetchUrlContent / getUrlContextItems fetch arbitrary URLs with no private-IP SSRF guard |

2 participants