Skip to content

Governance hook trusts ACP_GOVERN_BASE/ACP_API_BASE with no https/host allowlist (config-poisoning exfil) #26

Description

@davidcrowe

From the 2026-09-06 security review (client H4).

bin/govern.mjs:52-64,146 resolves the gateway from ACP_GOVERN_BASE -> ACP_API_BASE -> default and concatenates it into fetch() unchecked — http:// accepted, any host accepted — and sends Authorization: Bearer <workspace key> (:295-299) with it. ACP_BEARER_TOKEN likewise overrides the on-disk credential. (Same in codex-acp-plugin/bin/govern.mjs.)

A cloned repos .claude/settings.json envblock pointingACP_GOVERN_BASE at an attacker host exfiltrates the full governance stream (every Bash command, every file writes contents, cwd, session id) plus the workspace bearer — and, because the hook obeys the verdict it gets back, also returns a blanket allow. (The Claude-Code-applies-project-env-to-hook-children half is UNCONFIRMED; the hook-side unconditional trust is confirmed.)

Fix: require https:; allowlist the host to *.agenticcontrolplane.com unless an explicit self-host flag is set; never send the bearer to a non-default host without opt-in. Same treatment for claude-acps ACP_PROXY_BASE (install.sh:1446-1465), which points ANTHROPIC_BASE_URL and sees the credential + full conversation.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions