fix(): fix Critical command injection vulnerability + cross-platform breakage in CCTV image proxy - #244
Open
Arielpetit wants to merge 1 commit into
Conversation
…breakage in CCTV image proxy
Author
|
@simplifaisoul @sam1am @javierpr0 Can you please review this PR? |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
PR: Replace
execSync/curl.exewith Nativefetchin CCTV Image ProxyIssue
The CCTV image proxy (
src/app/api/cctv/proxy/route.ts:77) contained a critical command injection vulnerability and a cross-platform compatibility issue.The
curlFetchfunction executed a shell command usingexecSync:This introduced two separate problems:
curl.exeis the Windows binary name and does not exist on Linux, causing production deployments to fail.urlwas interpolated directly into a shell command, creating a command injection vulnerability.Fix
Replaced the
execSync/curl.exeimplementation with the native asynchronousfetchAPI.Changes include:
child_processimport.lenientFetch(url)helper built onfetch.AbortController.ALLOWED_HOSTSallowlist before issuing the request, preventing SSRF.Behavior
cdn.skylinewebcams.com)curl.exenot found)200)403 {"error":"Forbidden domain: ..."}urlparameter400 {"error":"Missing url parameter"}400 {"error":"Invalid URL"}AbortControllerFiles Changed
src/app/api/cctv/proxy/route.tsexecSync/child_processusage and replacedcurlFetch()with asynclenientFetch()using the nativefetchAPI.Verification
npm test— 9 passed, 1 skippednpm run build— Compiled successfullycurltesting — Success path and all error cases verified