Skip to content

fix(security): close the five open CodeQL alerts on main - #719

Merged
keysersoft merged 2 commits into
mainfrom
keysersoft/codeql-redos
Sep 25, 2026
Merged

keysersoft merged 2 commits into
mainfrom
keysersoft/codeql-redos

Conversation

@keysersoft

Copy link
Copy Markdown
Contributor

Closes every high-severity CodeQL alert currently open on main.

Alert Where Fix
js/polynomial-redos #112, #113 (open since May) graphql-builtins.ts slugifyForPrefix and the schema-URL trim were polynomial on long runs of _ / /. Both are now single linear passes. A test compares the new slug with the old regex on 2,000 random strings and checks that 50,000 underscores return at once.
js/remote-property-injection #131, #166 rest.engine.ts The __rawquery fragment and form-encoded OAuth 1.0a bodies are parsed into plain objects keyed by the tool argument. The values are strings, so __proto__ could not pollute the prototype. __proto__, constructor and prototype are now skipped anyway, since no API names a parameter like that. Test included.
js/reflected-xss #407 mcp-endpoint.controller.ts The global tools/list answer echoes the request id in a text/event-stream body. That body is not renderable as HTML, but it now sends X-Content-Type-Options: nosniff.

The ReDoS GitHub flagged in a review comment on #716 (the e-mail check for OAuth 1.0a consumer keys) had already been replaced by looksLikeEmail before that PR merged. No alert is open for it on main.

Backend suite (5,654 tests), tsc and eslint are green.

- js/polynomial-redos x2 (graphql-builtins.ts, open since May):
  slugifyForPrefix trimmed underscores with /^_+|_+$/g and the schema URL
  dropped trailing slashes with /\/+$/, both polynomial on long runs of the
  same character. Replaced with single linear passes; a test checks the new
  slug against the old regex on 2,000 random strings and that 50,000
  underscores return at once.
- js/remote-property-injection x2 (rest.engine.ts): the __rawquery fragment
  and form-encoded OAuth 1.0a bodies are parsed into plain objects keyed by
  whatever the tool argument says. Values are strings, so __proto__ could not
  pollute the prototype, but __proto__, constructor and prototype are now
  skipped; no API names a parameter like that. Test included.
- js/reflected-xss (mcp-endpoint.controller.ts): the tools/list answer on the
  global endpoint echoes the request id into a text/event-stream body. Not
  renderable as HTML, but it now carries X-Content-Type-Options: nosniff so
  no browser sniffs it into one.

The ReDoS flagged on #716 (e-mail check for OAuth 1.0a consumer keys) was
already replaced by looksLikeEmail before that PR merged; no alert is open
for it on main.
@keysersoft
keysersoft merged commit 529d008 into main Sep 25, 2026
12 checks passed
@keysersoft
keysersoft deleted the keysersoft/codeql-redos branch September 25, 2026 17:29
@github-actions github-actions Bot locked and limited conversation to collaborators Sep 25, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant