Skip to content

Security: SSRF validation on import_url endpoints#56

Open
nicdavidson wants to merge 4 commits intodevelopfrom
2026-04-security-scan
Open

Security: SSRF validation on import_url endpoints#56
nicdavidson wants to merge 4 commits intodevelopfrom
2026-04-security-scan

Conversation

@nicdavidson
Copy link
Copy Markdown

Summary

  • Add SSRF validation to import_url endpoints across Package, Import, and App services
  • Prevents internal network scanning via crafted import URLs

Test plan

  • Verify legitimate import URLs still work
  • Confirm internal/private IP ranges are blocked
  • Test with localhost, 169.254.x.x, 10.x.x.x URLs

oleksandrkits and others added 4 commits January 20, 2026 18:20
Added standard overview describing DreamFactory as a secure, self-hosted
enterprise data access platform for enterprise apps and on-prem LLMs.

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
The password reset link included &admin=1 for system administrators,
disclosing admin status in emails, browser history, and URL logs.
The frontend can determine admin status after reset via session info.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants