fix: reject invalid hosts matched via path substrings - #31
Merged
Merged
Conversation
Kikobeats
marked this pull request as ready for review
August 5, 2026 09:23
When exact matching is disabled for IPv6/punycode URLs, url-regex-safe can match a URL-looking substring in the path while the authority itself is not a valid HTTP host. Stop treating text fragments as unanchored, and require the origin to match whenever matching is unanchored. Co-authored-by: kikohumanbeatbox <kikohumanbeatbox@gmail.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01MTbj6CYXGsk6rhXx7J8SUP
Kikobeats
force-pushed
the
cursor/critical-bug-management-22ac
branch
from
August 5, 2026 15:26
63a29dd to
3f9ec94
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bug and impact
When matching runs with
exact: false(IPv6, punycode, and previously text fragments),url-regex-safecan match a URL-looking substring in the path while the actual authority is not a valid HTTP host.Concrete triggers that previously returned the href instead of
false:http://internal/https://example.com/#:~:text=x→ authority isinternal(http://internal/alone is rejected)http://metadata/https://example.com/#:~:text=xhttp://xn--internal/https://example.com/Callers that treat a truthy
url-httpresult as a validated HTTP(S) URL can accept single-label / otherwise-rejected hosts because a valid URL appears later in the path.This is distinct from #30 (credentialed-URL bypass). #30 rejects userinfo; this PR rejects invalid authorities accepted via unanchored path matches.
Root cause
exact: truealready accepts them.hrefcan succeed on a path substring without validating the origin.Fix
origin + '/'to match.Validation
npm testpasses (lint + Ava, 100% coverage)Note
Medium Risk
Changes URL acceptance rules for security-sensitive validation; behavior shifts for edge-case URLs (text fragments and IPv6/punycode) but is intended to reject previously dangerous false positives.
Overview
Tightens HTTP(S) URL validation so callers cannot treat a truthy result as a safe URL when the real authority is invalid but a second URL appears in the path (e.g.
http://internal/https://example.com/).Exact matching is no longer disabled for text-fragment hashes (
#:~:text=), since that was unnecessary and forced looser regex behavior.For IPv6 and punycode hosts (where
url-regex-safecannot useexact: true), validation now requires a second match on`${origin}/`after resettingregex.lastIndex, so a path substring cannot satisfy the check alone.Regression tests cover
internal,metadata, and punycode-style authorities with embeddedhttps://in the path.Reviewed by Cursor Bugbot for commit 3f9ec94. Bugbot is set up for automated code reviews on this repo. Configure here.