Skip to content

fix(security): prevent SSRF in task-automation enterprise API calls (CodeQL #116) - #3411

Merged
Marfuen merged 1 commit into
mainfrom
mariano/fix-ssrf-task-automation
Jul 15, 2026
Merged

Marfuen merged 1 commit into
mainfrom
mariano/fix-ssrf-task-automation

Conversation

@Marfuen

@Marfuen Marfuen commented Jul 15, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Fixes CodeQL js/request-forgery (alert #116, critical) — a server-side request forgery in the task-automation server actions.

callEnterpriseApi() builds new URL(endpoint, enterpriseApiUrl) and fetches it. getAutomationRunStatus() interpolated a user-provided runId directly into the endpoint path (/api/tasks-automations/runs/${runId}) with no encoding, so a crafted runId could inject extra path segments into the outgoing request URL. (The other callers pass user data via searchParams.append or the POST body, which don't influence the request target.)

Fix

Two layers:

  1. Encode the user value in the path — encodeURIComponent(runId) so it can only ever be a single, inert path segment.
  2. Origin allowlist guard at the sink (callEnterpriseApi) — resolve the URL against the configured enterprise API base and reject anything whose origin differs from it. This pins every request to the trusted host regardless of caller, so no user-derived value can redirect a request elsewhere.
const baseUrl = new URL(enterpriseApiUrl);
const url = new URL(endpoint, baseUrl);
if (url.origin !== baseUrl.origin) {
  throw new EnterpriseApiError('Invalid enterprise API endpoint', 400);
}

Notes / verification

  • No behavior change for legitimate calls — endpoints are already absolute paths on the configured base, so the origin always matches; runId values (trigger.dev run ids) are unaffected by encodeURIComponent.
  • @trycompai/app typecheck: the changed file compiles clean (the only typecheck failures are pre-existing test-file debt on main, unrelated to this change).
  • Single-file change; no dependency or lockfile changes.

Closes the code-scanning alert once CodeQL re-runs on this branch.

🤖 Generated with Claude Code


Summary by cubic

Prevents SSRF in task-automation enterprise API requests by pinning requests to the configured origin and encoding user input in URL paths. Fixes CodeQL js/request-forgery alert #116 without changing valid behavior.

  • Bug Fixes
    • Enforce origin check in callEnterpriseApi: resolve against base URL and reject endpoints whose origin differs.
    • Encode runId in getAutomationRunStatus with encodeURIComponent to prevent path injection.

Written for commit 8be58dc. Summary will update on new commits.

Review in cubic

Fixes CodeQL js/request-forgery (alert #116, critical). callEnterpriseApi
builds `new URL(endpoint, enterpriseApiUrl)` then fetches it; getAutomationRunStatus
interpolated a user-provided runId straight into the endpoint path
(`/api/tasks-automations/runs/${runId}`), so a crafted runId could inject
path segments into the request URL.

- Encode the user value in the path (encodeURIComponent(runId)).
- Add an origin allowlist guard in callEnterpriseApi: resolve the URL against
  the configured enterprise API base and reject anything whose origin differs,
  so no caller can redirect the request to another host.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@vercel

vercel Bot commented Jul 15, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
app Ready Ready Preview, Comment Jul 15, 2026 2:52pm
comp-framework-editor Ready Ready Preview, Comment Jul 15, 2026 2:52pm
1 Skipped Deployment
Project Deployment Actions Updated (UTC)
portal Skipped Skipped Jul 15, 2026 2:52pm

Request Review

@vercel
vercel Bot temporarily deployed to Preview – portal July 15, 2026 14:46 Inactive

@cubic-dev-ai cubic-dev-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

No issues found across 1 file

Confidence score: 5/5

  • Automated review surfaced no issues in the provided summaries.
  • No files require special attention.

Re-trigger cubic

@Marfuen
Marfuen merged commit dcec288 into main Jul 15, 2026
9 of 10 checks passed
@Marfuen
Marfuen deleted the mariano/fix-ssrf-task-automation branch July 15, 2026 14:51
claudfuen pushed a commit that referenced this pull request Jul 15, 2026
# [3.102.0](v3.101.2...v3.102.0) (2026-07-15)

### Bug Fixes

* **ci:** pin Syft 1.46.0 in SBOM action (1.42.3 can't parse bun.lock) ([#3415](#3415)) ([5f47024](5f47024))
* **ci:** scan bun.lock via file: input so the SBOM isn't empty ([#3414](#3414)) ([e47e6fd](e47e6fd))
* **deps:** override uuid to ^11.1.1 (Dependabot [#85](#85)) ([#3418](#3418)) ([598ff8c](598ff8c))
* **deps:** patch tmp and js-yaml in mcp-server (Dependabot [#58](https://github.com/trycompai/comp/issues/58)/[#59](https://github.com/trycompai/comp/issues/59)/[#71](https://github.com/trycompai/comp/issues/71)) ([#3412](#3412)) ([59a6b0f](59a6b0f))
* **deps:** remediate dependency security vulnerabilities ([#3403](#3403)) ([7577a37](7577a37))
* **deps:** remediate dependency security vulnerabilities (165→16, 4 critical→0) ([#3406](#3406)) ([d403e9c](d403e9c))
* **device-agent:** implement the installer-cleanup fix ([#3381](#3381)) ([0f7581b](0f7581b))
* **security:** prevent SSRF in task-automation enterprise API calls ([#3411](#3411)) ([dcec288](dcec288)), closes [#116](#116)
* **security:** resolve open CodeQL alerts (XSS, sanitization, workflow perms) ([#3419](#3419)) ([32329be](32329be)), closes [#108](#108) [js/xss-throu#dom](https://github.com/js/xss-throu/issues/dom) [#95](#95) [84/#85](#85)

### Features

* **framework-editor:** raise requirement description limit to 100,000 chars (FRAME-2) ([67c9f4a](67c9f4a))
@claudfuen

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 3.102.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

This branch was successfully deployed

2 active and 1 inactive deployments
Preview – comp-framework-editor — 8be58dce Deployed Jul 15, 2026 by vercel[bot]
Preview – app — 8be58dce Deployed Jul 15, 2026 by vercel[bot]
Preview – portal — 8be58dce Deployed Jul 15, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants