mirror of
https://github.com/BerriAI/litellm.git
synced 2026-10-03 02:22:24 +00:00
fix(cloud-agents): shell-quote install command interpolations (Greptile P1)
shlex.quote() the install_script_url, proxy_url, and raw_token before interpolating into the curl-pipe-sh one-liner. Without quoting, a proxy_url containing spaces or shell metacharacters (e.g. via a misconfig or the X-Forwarded-Host issue Greptile also flagged) could produce a malformed or exploitable command on the worker box.
This commit is contained in:
parent
45b1336115
commit
e4cce78b6e
1 changed files with 13 additions and 2 deletions
|
|
@ -19,6 +19,7 @@ matches the existing virtual-key hashed-token pattern.
|
|||
|
||||
import hashlib
|
||||
import secrets
|
||||
import shlex
|
||||
from dataclasses import dataclass
|
||||
from datetime import datetime, timedelta, timezone
|
||||
from typing import Optional
|
||||
|
|
@ -86,8 +87,18 @@ def build_install_command(
|
|||
Kept as a helper (not f-string at the callsite) so tests can lock the
|
||||
exact format and so we can swap the install host without touching
|
||||
endpoint code.
|
||||
|
||||
All operator-controlled values (`proxy_url`, `raw_token`, and the
|
||||
install script URL) are run through `shlex.quote` before interpolation
|
||||
so that spaces, quotes, or other shell metacharacters in any of them
|
||||
can't break out of the install command. The proxy URL is otherwise
|
||||
not validated here — the caller is responsible for verifying the
|
||||
host (see `worker_endpoints._resolve_proxy_url`).
|
||||
"""
|
||||
quoted_url = shlex.quote(install_script_url)
|
||||
quoted_proxy = shlex.quote(proxy_url)
|
||||
quoted_token = shlex.quote(raw_token)
|
||||
return (
|
||||
f"curl -fsS {install_script_url} | sh -s -- "
|
||||
f"--proxy {proxy_url} --token {raw_token}"
|
||||
f"curl -fsS {quoted_url} | sh -s -- "
|
||||
f"--proxy {quoted_proxy} --token {quoted_token}"
|
||||
)
|
||||
|
|
|
|||
Loading…
Add table
Reference in a new issue