fix(fetch): guard against private-IP and cloud metadata SSRF (#4838) - #4890
Open
MustafaKemal0146 wants to merge 1 commit into
Open
MustafaKemal0146 wants to merge 1 commit into
MustafaKemal0146 wants to merge 1 commit into
Conversation
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Resolves #4838
This PR adds Server-Side Request Forgery (SSRF) protection to
mcp-server-fetch:fetch_urlandcheck_may_autonomously_fetch_urlbefore issuing requests.127.0.0.1,::1,localhost), RFC1918 private IP subnets (10.0.0.0/8,172.16.0.0/12,192.168.0.0/16), link-local addresses (169.254.0.0/16,fe80::/10), reserved/multicast/unspecified addresses, and cloud metadata endpoints (169.254.169.254,100.100.100.100).httpxrequest event hook (_validate_request_host) to prevent open redirects from reaching private or metadata endpoints.FETCH_ALLOW_PRIVATE_IPSto"1"or"true"(case-insensitive).Rationale
Without this check, an LLM or malicious user-controlled prompt can instruct
mcp-server-fetchto query loopback or private services (such as local administrative consoles, Docker daemon APIs, or internal microservices) or fetch cloud instance metadata (AWS, GCP, Azure, Alibaba Cloud) containing temporary IAM credentials and configuration secrets. Validating destination hostnames and redirect targets mitigates these attack vectors.Test Plan
TestIsPrivateOrRestrictedHostcovering loopback, private subnets, cloud metadata IPs,.localdomains, public domains, and environment variable override.TestSSRFProtectionInFetchUrltesting direct fetch blocks on127.0.0.1,localhost, RFC1918 IPs, metadata IPs, IPv6 loopback, environment variable bypass, public URL handling, and redirect-to-private/metadata blocking.TestSSRFProtectionInRobotsTxttesting robots.txt check on loopback/localhost/metadata and redirect blocking.uv run pytestinsrc/fetch.uv run pyright(0 errors) and formatting/lint withuv run ruff check(clean).Disclosure: Implemented with AI assistance under human review.