From 58431102b768b5493efa6911527ee3c9aef4ed3e Mon Sep 17 00:00:00 2001 From: anupamme Date: Sat, 26 Sep 2026 17:22:45 +0000 Subject: [PATCH] fix: multi_agent.cwe-494 security vulnerability Automated security fix generated by OrbisAI Security --- src/utils/Updater/index.js | 27 ++++++++++++++++++++++++++- 1 file changed, 26 insertions(+), 1 deletion(-) diff --git a/src/utils/Updater/index.js b/src/utils/Updater/index.js index 718097c..aae0204 100644 --- a/src/utils/Updater/index.js +++ b/src/utils/Updater/index.js @@ -10,6 +10,26 @@ const normalizeArch = (architecture) => { } }; +/** + * Verify that a URL is HTTPS and hosted on a trusted CodeDead domain, to + * ensure update/download links from the remote API cannot be tampered with + * (e.g. via a compromised or MITM'd API response) to point to an untrusted host. + * @param url The URL to validate + * @returns {boolean} True if the URL is trusted, otherwise false + */ +const isTrustedUrl = (url) => { + try { + const parsed = new URL(url); + return ( + parsed.protocol === 'https:' && + (parsed.hostname === 'codedead.com' || + parsed.hostname.endsWith('.codedead.com')) + ); + } catch { + return false; + } +}; + const Updater = (os, architecture, currentVersion) => { /** * Check whether version b is newer than version a @@ -59,7 +79,12 @@ const Updater = (os, architecture, currentVersion) => { ); const version = normalizeVersion(update.semver); - if (!platform || !version) { + if ( + !platform || + !version || + !isTrustedUrl(platform.downloadUrl) || + (platform.infoUrl && !isTrustedUrl(platform.infoUrl)) + ) { return data; }