Commit 53692a8
committed
fix(devframe): reject non-loopback DNS origins beginning with 127.
isLoopbackHostname classified any hostname starting with '127.' as
loopback, so an attacker-controlled DNS name like 127.attacker.example
passed the loopback origin gate that guards the RPC/MCP surface. Because
every WS/SSE/MCP transport and the origin registry funnel through this
check, a cross-origin browser page could defeat the DNS-rebinding /
cross-site WebSocket-hijacking mitigation and reach privileged RPC.
Match the IPv4 loopback case structurally instead: the whole hostname
must be a canonical dotted-decimal literal in 127.0.0.0/8. Genuine
loopback addresses (127.0.0.1, 127.5.5.5) stay allowed; 127.* DNS names
are rejected.
CWE-346, CWE-13851 parent a55f3d5 commit 53692a8
2 files changed
Lines changed: 47 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
226 | 226 | | |
227 | 227 | | |
228 | 228 | | |
| 229 | + | |
| 230 | + | |
| 231 | + | |
| 232 | + | |
| 233 | + | |
| 234 | + | |
| 235 | + | |
| 236 | + | |
| 237 | + | |
| 238 | + | |
| 239 | + | |
| 240 | + | |
| 241 | + | |
| 242 | + | |
| 243 | + | |
229 | 244 | | |
230 | 245 | | |
231 | | - | |
232 | | - | |
| 246 | + | |
| 247 | + | |
| 248 | + | |
| 249 | + | |
| 250 | + | |
| 251 | + | |
| 252 | + | |
| 253 | + | |
| 254 | + | |
| 255 | + | |
| 256 | + | |
| 257 | + | |
| 258 | + | |
| 259 | + | |
| 260 | + | |
| 261 | + | |
| 262 | + | |
| 263 | + | |
233 | 264 | | |
234 | 265 | | |
235 | 266 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
340 | 340 | | |
341 | 341 | | |
342 | 342 | | |
| 343 | + | |
| 344 | + | |
| 345 | + | |
| 346 | + | |
| 347 | + | |
| 348 | + | |
| 349 | + | |
| 350 | + | |
| 351 | + | |
| 352 | + | |
| 353 | + | |
343 | 354 | | |
344 | 355 | | |
| 356 | + | |
| 357 | + | |
| 358 | + | |
345 | 359 | | |
346 | 360 | | |
347 | 361 | | |
| |||
0 commit comments