Skip to content

daily 2026-09-24: scan #111 superdesigndev/treg + boss-agent-cli precondition correction - #160

Merged
elfrost merged 2 commits into
mainfrom
daily/2026-09-24
Sep 24, 2026
Merged

elfrost merged 2 commits into
mainfrom
daily/2026-09-24

Conversation

@elfrost

@elfrost elfrost commented Sep 24, 2026

Copy link
Copy Markdown
Owner

Daily run — 2026-09-24

Phase 1 — status sweep

  • Polled 14 filed GHSAs (read-only GET): no state changes. viseron + mercury remain draft/accepted (not published); the rest triage; AudioMuse-AI stays closed. resolved_count stays 25.
  • boss-agent-cli GHSA-xp54-2hxc-w78q precondition corrected. The filed "auto-starts on first browser command, 4h idle window" was wrong both ways: start_daemon_background() had zero callers at 73e020f (maintainer removed it as dead code in #440 two hours after filing → manual start only), and the idle exit requires no extension connection, so it never fires while the extension is connected. Corrected the advisory via PATCH description (dated block + strike-through, no silent rewrite; state/severity/CWEs/vulnerabilities verified unchanged by GET), and the public post + scan-log the same day (commit 5f76788).
  • Octop (sent 09-21) still awaiting maintainer ack; no upstream commits to the flagged files.

Phase 2–5 — scan #111: superdesigndev/treg

"OpenRouter for agent tools" (3k★, source-available, hosted + self-hostable), a multi-tenant credential-proxy. 96 findings at medium+, 1 real after curation — withheld.

  • The real finding (Medium, hand-review, not scanner): treg's call-time SSRF guard host_is_public is wired into the /call relay but not into a sibling server-side outbound path a plain member can drive. The registration-time check there is static and allows any DNS name (its own docstring defers to the call-time check), so a name resolving to an internal address reaches the request unchecked → member-authenticated, semi-blind SSRF reaching internal + cloud-metadata from treg's egress. Injected credential on the path is the member's own → not cross-tenant theft. Confirmed by running treg's own two guard functions side by side on a host that resolves internally (registration True, call-time False).
  • Channel: strict-norm — SECURITY.md forbids public vuln issues, PVR disabled ({"enabled":false}), names an email. Manual queue depth 0 → email acceptable. Private email drafted + staged to jason@superdesign.dev; the send is the operator's step.
  • Published: post withheld at class level; index + scan-log + counts bumped 110 → 111; verdicts.json validated (exit 0) and copied to corpus/.
  • Coverage: partial — Semgrep hit a Windows per-file temp error on five modules (recovered by a targeted re-run of just those five); pip-audit left uv.lock unaudited, Trivy read it. Neither touches the finding.

No public issue/PR filed (strict-norm + private channel).

🤖 Generated with Claude Code

elfrost and others added 2 commits September 24, 2026 09:06
… while connected)

The post and the private report both described the bridge exposure as "a
bounded window". Checked against 73e020f, both halves were wrong: nothing
calls start_daemon_background() (the maintainer removed it as dead code in
#440), so the user must start bridge mode by hand; and the idle exit
requires no extension connection, so it never fires while the browser side
is connected. The advisory was corrected the same day with a dated block;
the finding, the fix and the severity are unchanged.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…nguarded sibling, reported privately)

96 findings at medium+, 1 real after curation — withheld, reported privately by
email (SECURITY.md forbids public issues; PVR disabled). The real finding: treg's
call-time SSRF guard (host_is_public) is wired into the /call relay but not into a
sibling server-side outbound path a plain member can drive; the registration-time
check there is static and allows any DNS name, so a name resolving to an internal
address reaches the request unchecked. Member-authenticated, semi-blind, reaches
internal + cloud-metadata from treg's egress; the injected credential is the
member's own (not cross-tenant theft) — graded Medium. Confirmed by running treg's
own two guard functions side by side on a host that resolves internally.

Post published with the finding withheld at class level; private email drafted and
staged (the send is the operator's step). verdicts.json validated (exit 0) and
copied to corpus/. Also updates the boss-agent-cli forward pointer.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@elfrost
elfrost merged commit 1b94592 into main Sep 24, 2026
2 checks passed
@elfrost
elfrost deleted the daily/2026-09-24 branch September 24, 2026 13:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant