Security hardening suite: RCE, SSRF, owner-scope, path confinement #938
Labels
No labels
area:chat
area:core
area:llm
area:routes
area:tools
bug
documentation
duplicate
enhancement
good first issue
help wanted
invalid
question
refactor
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
sleepy/odysseus#938
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Overview
Adopt upstream security hardening across multiple attack surfaces. These are active vulnerability fixes our fork lacks.
Upstream References
MCP RCE (Agent-Path Injection)
manage_mcp "add"to close the agent-path RCE. The agent can no longer inject arbitrary MCP commands through tool calls.93569b1 fix(security): allowlist manage_mcp "add" to close the agent-path RCE (#4433)../odysseus_upstream/src/tool_implementations.py— see_validate_mcp_command()and_mcp_allowed_commands()Agent Loop Hardening
4e47774 harden(agent-loop): wrap non-native tool results as untrusted data (#1629)../odysseus_upstream/src/agent_loop.pySSRF / Web Fetch Guardrails
web_fetchwith truncation notice and hard ceiling.fire_and_forgetfor webhook SSRF resilience.074a1e6,2196869../odysseus_upstream/src/endpoint_resolver.py,../odysseus_upstream/tests/test_webhook_ssrf_resilience.pyOwner Scope Hardening
Multiple owner-scope fixes upstream:
7b09491— check-in calendar digest leaks every users events (missing owner scope) #1925422f23f— scope memory server by owner #4315260ce8b— enforce MCP owner boundaries #4335facc50c— attribute bearer-token actions to token owner #40540750486— fail closed when unauthenticated request reaches owner-scoped routes #4062f602819— scope API-token model listing #4292b58af42— require chat scope for model inventory #4319Path Confinement
745c10e— confine gallery image path resolution #435281e7074— confine replacement image path #4285facc50c— research handler path confinementCardDAV Password Encryption
Implementation Plan
src/tool_security.pyagainst upstreamsrc/tool_security.py../odysseus_upstream/tests/test_manage_mcp_command_allowlist.py,test_tool_output_prompt_injection.py,test_owner_isolation*.py, etc.)Priority
Critical — these are vulnerability fixes, not features.