Commit c9df82a
committed
security: fix SSRF vulnerability in URL path parameter replacement
- Add urllib.parse.quote to safely encode path parameters
- Use safe='' to encode all special characters including '/', ':', '@'
- Prevents attackers from injecting malicious hosts or internal service paths
- Applies to both explicit PATH parameters and default path replacement logic1 parent 0a14357 commit c9df82a
1 file changed
+7
-2
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
8 | 8 | | |
9 | 9 | | |
10 | 10 | | |
| 11 | + | |
11 | 12 | | |
12 | 13 | | |
13 | 14 | | |
| |||
147 | 148 | | |
148 | 149 | | |
149 | 150 | | |
150 | | - | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
151 | 154 | | |
152 | 155 | | |
153 | 156 | | |
154 | 157 | | |
155 | 158 | | |
156 | 159 | | |
157 | 160 | | |
158 | | - | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
159 | 164 | | |
160 | 165 | | |
161 | 166 | | |
| |||
0 commit comments