daily 2026-09-24: scan #111 superdesigndev/treg + boss-agent-cli precondition correction - #160
Merged
Merged
Conversation
… while connected) The post and the private report both described the bridge exposure as "a bounded window". Checked against 73e020f, both halves were wrong: nothing calls start_daemon_background() (the maintainer removed it as dead code in #440), so the user must start bridge mode by hand; and the idle exit requires no extension connection, so it never fires while the browser side is connected. The advisory was corrected the same day with a dated block; the finding, the fix and the severity are unchanged. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
…nguarded sibling, reported privately) 96 findings at medium+, 1 real after curation — withheld, reported privately by email (SECURITY.md forbids public issues; PVR disabled). The real finding: treg's call-time SSRF guard (host_is_public) is wired into the /call relay but not into a sibling server-side outbound path a plain member can drive; the registration-time check there is static and allows any DNS name, so a name resolving to an internal address reaches the request unchecked. Member-authenticated, semi-blind, reaches internal + cloud-metadata from treg's egress; the injected credential is the member's own (not cross-tenant theft) — graded Medium. Confirmed by running treg's own two guard functions side by side on a host that resolves internally. Post published with the finding withheld at class level; private email drafted and staged (the send is the operator's step). verdicts.json validated (exit 0) and copied to corpus/. Also updates the boss-agent-cli forward pointer. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Daily run — 2026-09-24
Phase 1 — status sweep
draft/accepted (not published); the resttriage; AudioMuse-AI staysclosed. resolved_count stays 25.start_daemon_background()had zero callers at 73e020f (maintainer removed it as dead code in #440 two hours after filing → manual start only), and the idle exit requires no extension connection, so it never fires while the extension is connected. Corrected the advisory viaPATCHdescription (dated block + strike-through, no silent rewrite; state/severity/CWEs/vulnerabilities verified unchanged by GET), and the public post + scan-log the same day (commit 5f76788).Phase 2–5 — scan #111: superdesigndev/treg
"OpenRouter for agent tools" (3k★, source-available, hosted + self-hostable), a multi-tenant credential-proxy. 96 findings at
medium+, 1 real after curation — withheld.host_is_publicis wired into the/callrelay but not into a sibling server-side outbound path a plain member can drive. The registration-time check there is static and allows any DNS name (its own docstring defers to the call-time check), so a name resolving to an internal address reaches the request unchecked → member-authenticated, semi-blind SSRF reaching internal + cloud-metadata from treg's egress. Injected credential on the path is the member's own → not cross-tenant theft. Confirmed by running treg's own two guard functions side by side on a host that resolves internally (registrationTrue, call-timeFalse).{"enabled":false}), names an email. Manual queue depth 0 → email acceptable. Private email drafted + staged to jason@superdesign.dev; the send is the operator's step.verdicts.jsonvalidated (exit 0) and copied tocorpus/.uv.lockunaudited, Trivy read it. Neither touches the finding.No public issue/PR filed (strict-norm + private channel).
🤖 Generated with Claude Code