mirror of
https://github.com/langflow-ai/langflow.git
synced 2026-07-23 21:21:20 +08:00
* fix(security): block socket/urllib network egress in component code scanner Completes the CVE-2026-33873 / GHSA-v8hw-mh8c-jxfc fix. The AST scanner `scan_code_security()` blocked `subprocess` but omitted `socket` and `urllib`, so LLM-generated / assistant-submitted component code importing `socket.connect()` or `urllib.request.urlopen()` passed the scan and still executed server-side during validation — enabling raw-socket reverse shells, raw exfiltration, and `urllib` SSRF (incl. `file://` local reads and cloud IMDS credential theft). Add the network/IPC stdlib attack class to the blocklist (same class as `subprocess`): - whole modules: socket, socketserver, ftplib, telnetlib, smtplib, poplib, imaplib, nntplib, xmlrpc, pty - submodules (precise, preserving safe siblings): urllib.request, urllib.error, http.client, http.server - os.dup2 / os.dup attribute calls (socket->shell fd redirection) High-level HTTP via `requests`/`httpx` stays allowed by design (legit API components need it), and the safe `urllib.parse` / `from http import HTTPStatus` siblings remain importable. This scanner is defense-in-depth, not a full sandbox (see #12787); residual SSRF via the permitted HTTP clients is unchanged. Adds regression tests covering each blocked module, the reporter PoC payloads, and the safe-sibling no-regression cases. * fix(security): resolve import-alias and wildcard-import scanner bypasses The component-code scanner matched restricted module members only by the literal module name, so `import os as o; o.dup2(...)` (alias) and `from os import *; dup2(...)` (wildcard) slipped past the os.*/sys.* attribute checks — `os`/`sys` are importable as whole modules, only their members are restricted. - track import aliases (incl. `import os.path as p`) and resolve them in the attribute-call and attribute-read checks - track `from <mod> import *` and treat bare references to restricted members as direct attribute access (calls via _check_name_call, reads via visit_Name), using member sets derived from the existing tables so they stay in sync - collect imports in an order-independent pre-pass Safe siblings still pass (`o.path.join`, aliased `requests`, wildcard `getcwd`/`listdir`). Adds regression tests for both bypass patterns plus no-regression cases. * fix(security): flag dotted submodule access (urllib.request/http.client) A bare `import urllib` / `import http` is allowed (the package root is safe for urllib.parse / http.HTTPStatus), but at runtime the assistant import chain has already loaded `urllib.request` and `http.client`, so `import urllib; urllib.request.urlopen(...)` reaches the blocked submodule without an explicit submodule import and scanned as safe — re-opening the SSRF / HTTP-client path. Detect dotted attribute chains that resolve to a blocked submodule in visit_Attribute (alias-resolved on the root name, exact-match per node to avoid double-flagging the chain). Catches the no-import form too (pure runtime-preload reliance) and `import urllib as u; u.request...`. Safe siblings still pass: urllib.parse.*, http.HTTPStatus, os.path.*. Adds regression tests for the bare-import and alias bypass variants.