mirror of
https://github.com/BerriAI/litellm.git
synced 2026-09-23 00:41:40 +00:00
Cursor security review flagged that run_claude() forwarded the entire parent environment to the externally installed claude CLI binary. In the PR gate flow the binary is dynamically installed from npm, and the surrounding job loads every upstream provider credential (ANTHROPIC_API_KEY, AWS_*, AZURE_FOUNDRY_*, VERTEXAI_CREDENTIALS, GITHUB_TOKEN, ...) into its env so the proxy can route requests. A compromised CLI release would have read access to all of them — even though the CLI itself only ever talks to the proxy via the explicit ANTHROPIC_BASE_URL/ANTHROPIC_AUTH_TOKEN we set. Build the subprocess env from a small allowlist of process-runtime vars (PATH, HOME, NVM_DIR, locale) rather than inheriting all of os.environ. Caller-supplied extra_env still rides on top, which is the sanctioned way for tests to opt-in to passing additional vars (e.g. extended_thinking sets MAX_THINKING_TOKENS). Add unit tests pinning the contract: PATH/HOME flow through, secrets do not, and extra_env can still override anything. Co-authored-by: Mateo Wang <mateo-berri@users.noreply.github.com> |
||
|---|---|---|
| .. | ||
| _builder_unit_tests | ||
| _driver_unit_tests | ||
| _pr_gate_unit_tests | ||
| basic_messaging_non_streaming | ||
| basic_messaging_streaming | ||
| cron_vm | ||
| extended_thinking | ||
| pdf_input | ||
| prompt_caching_1h | ||
| prompt_caching_5m | ||
| thinking_with_tool_use | ||
| tool_use | ||
| tool_use_streaming | ||
| vision | ||
| web_search | ||
| __init__.py | ||
| cli_driver.py | ||
| conftest.py | ||
| manifest.yaml | ||
| matrix_builder.py | ||
| pr_gate_version_resolver.py | ||
| rate_limiter.py | ||
| run_compat.sh | ||
| sample_compatibility-matrix.json | ||
| test_config.yaml | ||