Skip to content

docs: scan #110 — can4hou6joeng4/boss-agent-cli (browser-bridge loopback, filed private) - #159

Merged
elfrost merged 1 commit into
mainfrom
daily/2026-09-23-boss-agent-cli
Sep 23, 2026
Merged

elfrost merged 1 commit into
mainfrom
daily/2026-09-23-boss-agent-cli

Conversation

@elfrost

@elfrost elfrost commented Sep 23, 2026

Copy link
Copy Markdown
Owner

Scan #110. One real finding, filed privately as GHSA-xp54-2hxc-w78q (High, triage).

Strict-norm channel. The project's SECURITY.md forbids public vulnerability issues and points to GitHub private vulnerability reporting, which is enabled. The report went through PVR and was accepted into triage on the first attempt, with the vulnerabilities array (the viseron rule holds). The post withholds detail at class level until the advisory resolves.

The finding. Desktop-loopback-inversion: a local Browser Bridge daemon that binds neither who may call it nor which host the request claims, driving privileged browser actions against a site where the operator is authenticated. No scanner rule reported it — it is the absence of a check on an otherwise-working channel. Confirmed with a server-side exploit primitive against the shipped daemon plus a read of the extension source. Graded High not Critical on an honest precondition (the bridge must be actively running), and the fix was written before it was named — narrow, verified not to break the tool's own two legitimate clients.

Curation. 26 findings at medium+, every scanner hit dismissed: 8 SQL identifier FPs (5 high), 8 mutable-action-tag flood, two sha1 dedup ids, two local/dev urllib calls, a loopback health-check react hit, a py3.7 compat rule. verdicts.json validated (exit 0) and copied to corpus/.

  • new post (withheld, class level)
  • index: new row (private), counts 109 → 110
  • scan log: new prose bullet, count 109 → 110
  • corpus verdicts row

🤖 Generated with Claude Code

…ack, filed private)

One real finding, filed privately as GHSA-xp54-2hxc-w78q (High, triage). The
project's SECURITY.md forbids public vulnerability issues and points to GitHub
private vulnerability reporting, which is enabled; the report was accepted into
triage first try (with the vulnerabilities array — the viseron rule holds).

The finding is the desktop-loopback-inversion class: a local Browser Bridge
daemon that binds neither who may call it nor which host the request claims,
driving privileged browser actions against a site where the operator is
authenticated. No scanner rule reported it — it is the absence of a check on an
otherwise-working channel. Confirmed with a server-side exploit primitive
against the shipped daemon plus a read of the extension source; graded High on
an honest precondition (the bridge must be actively running). Detail withheld
from the post at class level until the advisory resolves.

Curation: 26 findings at medium+, all scanner hits dismissed — 8 SQL identifier
FPs (5 high), 8 mutable-action-tag flood, sha1 dedup ids, local/dev urllib,
a loopback health-check react hit, a py3.7 compat rule. verdicts.json validated
(exit 0) and copied to corpus/.

- new post docs/scans/can4hou6joeng4-boss-agent-cli.md (withheld, class level)
- index: new row (private), scan counts 109 -> 110
- scan log: new prose bullet, count 109 -> 110
- corpus/verdicts/can4hou6joeng4-boss-agent-cli.json

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@elfrost
elfrost merged commit f2fef7e into main Sep 23, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant