Skip to content

fetchUrlContent / getUrlContextItems fetch arbitrary URLs with no private-IP SSRF guard | #13310

Description

@tiagovilasboas

Static review of public source at commit 5522c6f44ca0. No traffic was sent to any Continue environment.

The built-in “Read URL” tool delegates to getUrlContextItems, which performs an unrestricted fetch:

core/context/providers/URLContextProvider.ts:

export async function getUrlContextItems(
  query: string,
  fetchFn: FetchFunction,
): Promise<ContextItem[]> {
  const url = new URL(query);
  const icon = await fetchFavicon(url);
  const resp = await fetchFn(url);
  // ...
}

core/tools/implementations/fetchUrlContent.ts only truncates length. Policy is allowedWithPermission, which helps for intentional calls, but there is still no allowlist / private-IP rejection before the host-side fetch runs. From an IDE/agent host that can reach RFC1918 or link-local addresses, a model-chosen URL (or open redirect) is classic SSRF-shaped egress.

Suggested change:

  • Before fetchFn, resolve and reject private/special-purpose/metadata destinations (and re-check redirect targets if the fetch follows redirects).
  • Optional allowedHosts / allowPrivateNetwork config for power users.
  • Keep the existing permission prompt.

Severity: medium as missing SSRF egress control on an agent URL tool; mitigated somewhat by allowedWithPermission. No proof-of-concept.

Happy to send a focused PR if this direction is useful.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions