Vito Sansevero
8399fad96b
fix: prevent URL substring sanitization bypass attacks
Fixed incomplete URL substring sanitization vulnerability (CodeQL alert)
by implementing proper domain validation using urlparse().netloc instead
of substring checking with 'in url'.
Changes:
- civitai.py: Added explicit domain validation before processing URLs
- Only allow exact matches: 'civitai.com' and 'www.civitai.com'
- Reject URLs like 'evil.com/civitai.com' or 'civitai.com.evil.com'
- detector.py: Improved URL detection methods
- _is_civitai_url: Changed from 'in parsed.netloc' to exact match
- _is_huggingface_url: Added allowlist of valid HF domains
- Supports: huggingface.co, www.huggingface.co, cdn.huggingface.co,
cdn-lfs.huggingface.co
Security Impact:
Prevents subdomain attacks and URL smuggling where malicious URLs could
bypass validation by including legitimate domain names as substrings:
- https://evil.com/civitai.com/malicious
- https://civitai.com.evil.com/models/123
- https://subdomain.civitai.com/attack
All security tests pass with 100% malicious URL rejection rate.
2025-10-05 07:32:18 -07:00
..
2025-08-10 06:33:12 -07:00
2025-08-27 09:44:16 -07:00
2025-10-05 07:32:18 -07:00
2025-10-05 05:39:35 -07:00