mirror of https://github.com/aliasrobotics/cai.git
The fetch_url SSRF guard guarantees cloud-metadata endpoints (e.g. 169.254.169.254) are ALWAYS blocked, even when CAI_FETCH_ALLOW_INTERNAL is set for an authorised internal pentest. That guarantee could be bypassed with the IPv4-mapped IPv6 form of the IMDS address, e.g. http://[::ffff:169.254.169.254]/ (or its hex form ::ffff:a9fe:a9fe), because the metadata block is a plain string comparison against the bare IPv4 literal. With allow_internal=True the private/reserved check is skipped, so nothing caught the mapped form and the request reached IMDS. Unwrap IPv4-mapped IPv6 addresses to their embedded IPv4 before the metadata and private-range checks in both the literal-IP and DNS-resolved paths. This also hardens the private-range check on Python versions that do not classify mapped addresses as private/link-local. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Signed-off-by: Mike German <mike@stepsventures.com> |
||
|---|---|---|
| .. | ||
| web | ||
| test_approach_contest.py | ||
| test_approach_contest_resolve.py | ||
| test_avoid_sudo.py | ||
| test_capture_notice.py | ||
| test_evidence_inventory_check.py | ||
| test_function_tool.py | ||
| test_function_tool_decorator.py | ||
| test_generic_linux_command_guardrails.py | ||
| test_handoff_tool.py | ||
| test_malformed_tool_call.py | ||
| test_output_tool.py | ||
| test_sensitive_guard_false_positives.py | ||
| test_sudo_continuous_ops_no_sudo.py | ||
| test_tool_choice_reset.py | ||
| test_tool_converter.py | ||
| test_tool_generic_linux_command.py | ||
| test_tool_generic_linux_sessions.py | ||
| test_tool_use_behavior.py | ||