Files
langflow/src
Eric Hare 8c98cdf5cc fix(security): block socket/urllib network egress in component code scanner (#13784)
* fix(security): block socket/urllib network egress in component code scanner

Completes the CVE-2026-33873 / GHSA-v8hw-mh8c-jxfc fix. The AST scanner
`scan_code_security()` blocked `subprocess` but omitted `socket` and
`urllib`, so LLM-generated / assistant-submitted component code importing
`socket.connect()` or `urllib.request.urlopen()` passed the scan and still
executed server-side during validation — enabling raw-socket reverse
shells, raw exfiltration, and `urllib` SSRF (incl. `file://` local reads
and cloud IMDS credential theft).

Add the network/IPC stdlib attack class to the blocklist (same class as
`subprocess`):
- whole modules: socket, socketserver, ftplib, telnetlib, smtplib,
  poplib, imaplib, nntplib, xmlrpc, pty
- submodules (precise, preserving safe siblings): urllib.request,
  urllib.error, http.client, http.server
- os.dup2 / os.dup attribute calls (socket->shell fd redirection)

High-level HTTP via `requests`/`httpx` stays allowed by design (legit API
components need it), and the safe `urllib.parse` / `from http import
HTTPStatus` siblings remain importable. This scanner is defense-in-depth,
not a full sandbox (see #12787); residual SSRF via the permitted HTTP
clients is unchanged.

Adds regression tests covering each blocked module, the reporter PoC
payloads, and the safe-sibling no-regression cases.

* fix(security): resolve import-alias and wildcard-import scanner bypasses

The component-code scanner matched restricted module members only by the
literal module name, so `import os as o; o.dup2(...)` (alias) and
`from os import *; dup2(...)` (wildcard) slipped past the os.*/sys.*
attribute checks — `os`/`sys` are importable as whole modules, only their
members are restricted.

- track import aliases (incl. `import os.path as p`) and resolve them in
  the attribute-call and attribute-read checks
- track `from <mod> import *` and treat bare references to restricted
  members as direct attribute access (calls via _check_name_call, reads
  via visit_Name), using member sets derived from the existing tables so
  they stay in sync
- collect imports in an order-independent pre-pass

Safe siblings still pass (`o.path.join`, aliased `requests`, wildcard
`getcwd`/`listdir`). Adds regression tests for both bypass patterns plus
no-regression cases.

* fix(security): flag dotted submodule access (urllib.request/http.client)

A bare `import urllib` / `import http` is allowed (the package root is
safe for urllib.parse / http.HTTPStatus), but at runtime the assistant
import chain has already loaded `urllib.request` and `http.client`, so
`import urllib; urllib.request.urlopen(...)` reaches the blocked
submodule without an explicit submodule import and scanned as safe —
re-opening the SSRF / HTTP-client path.

Detect dotted attribute chains that resolve to a blocked submodule in
visit_Attribute (alias-resolved on the root name, exact-match per node to
avoid double-flagging the chain). Catches the no-import form too (pure
runtime-preload reliance) and `import urllib as u; u.request...`.

Safe siblings still pass: urllib.parse.*, http.HTTPStatus, os.path.*.
Adds regression tests for the bare-import and alias bypass variants.
2026-06-23 18:54:38 +00:00
..