Skip to content

fix(tools): reject dot path segments in tool request URLs - #8604

Merged
waleedlatif1 merged 2 commits into
stagingfrom
fix/tool-url-path-traversal
Oct 3, 2026
Merged

waleedlatif1 merged 2 commits into
stagingfrom
fix/tool-url-path-traversal

Conversation

@waleedlatif1

Copy link
Copy Markdown
Collaborator

Summary

  • Reject tool request URLs whose path contains a . or .. segment (incl. %2e spellings) before dispatch, so an id param interpolated into a URL template can't traverse to another endpoint
  • Central check in the shared request transport, so it covers every URL-builder tool
  • A hand-written HTTP Request URL containing a literal .. segment is now rejected too

Type of Change

  • Bug fix

Testing

  • tools/request-transport.test.ts: new traversal cases fail without the guard; registry probe now requires benign URLs to pass and injected .. ids to be rejected
  • tools/ + executor/handlers suites, lint, type-check, check:audits, docs-manifest:check, root bun run test (2 unrelated timing flakes, pass on rerun)

Checklist

  • Code follows project style guidelines
  • Self-reviewed my changes
  • Tests added/updated and passing (new tests pass the test-audit authoring gate)
  • No new warnings introduced
  • I confirm that I have read and agree to the terms outlined in the Contributor License Agreement (CLA)

🤖 Generated with Claude Code

@vercel

vercel Bot commented Oct 3, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

1 Skipped Deployment
Project Deployment Actions Updated
docs Skipped Skipped Oct 3, 2026 7:34pm UTC

Request Review

@greptile-apps

greptile-apps Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

RetriggerConfidence Score: 5/5

[Medium risk] Adds path traversal validation to tool request URLs.

The PR appears safe to merge; no outstanding blocking finding was established.

Summary

The PR adds a shared pre-dispatch check for dot path segments in external tool request URLs and tests both rejected traversal paths and allowed non-segment dots.

  • The latest revision tightens the registry probe’s assertions and aligns boundary-whitespace handling with URL parsing.

Reviews (2) · Last reviewed commit: "fix(tools): match URL parser boundary st..."

Comment thread apps/sim/tools/request-transport.test.ts Outdated

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 3 files

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread apps/sim/tools/url-path.ts
@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@greptile

@waleedlatif1

Copy link
Copy Markdown
Collaborator Author

@cubic-dev-ai review this PR

@cubic-dev-ai

cubic-dev-ai Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

@cubic-dev-ai review this PR

@waleedlatif1 I have started the AI code review. It will take a few minutes to complete.

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 3 files

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@waleedlatif1
waleedlatif1 merged commit 825e7e7 into staging Oct 3, 2026
33 checks passed
@waleedlatif1
waleedlatif1 deleted the fix/tool-url-path-traversal branch October 3, 2026 21:17

This branch was previously deployed

1 inactive deployment
Preview — 0b47551e Deployed Oct 3, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant