From ad62ce2b33c328083c1a0b69b8e93349edf0a7d9 Mon Sep 17 00:00:00 2001 From: Praveen Ghuge Date: Wed, 13 May 2026 22:31:06 +0530 Subject: [PATCH] fix(mavvrik): use urlparse.hostname to prevent userinfo bypass in domain validation Replace netloc.split(":")[0] with urlparse().hostname in both MavvrikInitRequest and MavvrikSettingsUpdate validators. The previous approach was bypassable via URL userinfo (e.g. https://api.mavvrik.dev:443@attacker.example/t) which would pass the allowlist check while HTTP clients connect to the attacker host. Co-Authored-By: Claude Sonnet 4.6 (1M context) --- litellm/types/proxy/mavvrik_endpoints.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/litellm/types/proxy/mavvrik_endpoints.py b/litellm/types/proxy/mavvrik_endpoints.py index 771aa42fb1e..ebdbc62e3de 100644 --- a/litellm/types/proxy/mavvrik_endpoints.py +++ b/litellm/types/proxy/mavvrik_endpoints.py @@ -37,7 +37,7 @@ class MavvrikInitRequest(BaseModel): def must_be_https_mavvrik_host(cls, v: str) -> str: if not v.startswith("https://"): raise ValueError("api_endpoint must be an HTTPS URL") - netloc = urlparse(v).netloc.split(":")[0] # strip port if present + netloc = (urlparse(v).hostname or "").lower() # strip userinfo/port if not any(netloc.endswith(suffix) for suffix in _MAVVRIK_ALLOWED_SUFFIXES): raise ValueError( f"api_endpoint host must be a Mavvrik domain " @@ -152,7 +152,7 @@ class MavvrikSettingsUpdate(BaseModel): return v if not v.startswith("https://"): raise ValueError("api_endpoint must be an HTTPS URL") - netloc = urlparse(v).netloc.split(":")[0] + netloc = (urlparse(v).hostname or "").lower() # strip userinfo/port if not any(netloc.endswith(suffix) for suffix in _MAVVRIK_ALLOWED_SUFFIXES): raise ValueError( f"api_endpoint host must be a Mavvrik domain "