From 6c69b1d502a78dc3af266f4b7e7113a48ae90510 Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Wed, 6 May 2026 14:18:44 +0000 Subject: [PATCH] fix(cron_vm): bind populator proxy to loopback only Cursor security review flagged that the cron VM proxy binds to 0.0.0.0 (litellm's default when --host is omitted) while running under the predictable default `LITELLM_MASTER_KEY=sk-cron-matrix`. On a VM where :PROXY_PORT is reachable, anything that can hit the port can authenticate with the predictable fallback secret and burn upstream provider credentials. The populator proxy is only ever talked to by the same-host pytest run (the health check and tests both use http://127.0.0.1:${PORT}), so there's no reason for it to listen on external interfaces. Pass `--host 127.0.0.1` explicitly. Co-authored-by: Mateo Wang --- tests/claude_code/cron_vm/run_daily.sh | 13 +++++++++++-- 1 file changed, 11 insertions(+), 2 deletions(-) diff --git a/tests/claude_code/cron_vm/run_daily.sh b/tests/claude_code/cron_vm/run_daily.sh index 7205fe01220..c2183067b3a 100755 --- a/tests/claude_code/cron_vm/run_daily.sh +++ b/tests/claude_code/cron_vm/run_daily.sh @@ -234,7 +234,16 @@ PROXY_CONFIG="${WORKTREE}/tests/claude_code/test_config.yaml" # 3. Boot the proxy # --------------------------------------------------------------------------- -log "starting proxy on :${PROXY_PORT}" +log "starting proxy on 127.0.0.1:${PROXY_PORT}" +# Bind the proxy to loopback only. The populator proxy is talked to +# exclusively by the pytest run on the same host (the health check and +# the test env set `LITELLM_PROXY_BASE_URL=http://127.0.0.1:...`), +# so there's no reason to expose it on the VM's external interfaces. +# Without `--host`, `litellm` defaults to 0.0.0.0, which combined with +# the predictable default `LITELLM_MASTER_KEY=sk-cron-matrix` would +# allow anything that can reach :${PROXY_PORT} on the VM to authenticate +# and burn upstream provider credentials. +# # `setsid` puts the proxy in its own session+pgroup so cleanup() can # SIGTERM the whole tree by passing the pgid as a negative pid. We # write that pid to a file so cleanup() doesn't need to remember a @@ -242,7 +251,7 @@ log "starting proxy on :${PROXY_PORT}" setsid env LITELLM_MASTER_KEY="${PROXY_API_KEY}" bash -c ' echo "$$" > "$0" cd "$1" - exec "$2" run litellm --config "$3" --port "$4" + exec "$2" run litellm --config "$3" --host 127.0.0.1 --port "$4" ' "${PROXY_PID_FILE}" "${WORKTREE}" "${WORKTREE_UV}" "${PROXY_CONFIG}" "${PROXY_PORT}" \ >"${WORKDIR}/proxy.log" 2>&1 & disown