Static review of public source at commit 5522c6f44ca0. No traffic was sent to any Continue environment.
The built-in “Read URL” tool delegates to getUrlContextItems, which performs an unrestricted fetch:
core/context/providers/URLContextProvider.ts:
export async function getUrlContextItems(
query: string,
fetchFn: FetchFunction,
): Promise<ContextItem[]> {
const url = new URL(query);
const icon = await fetchFavicon(url);
const resp = await fetchFn(url);
// ...
}
core/tools/implementations/fetchUrlContent.ts only truncates length. Policy is allowedWithPermission, which helps for intentional calls, but there is still no allowlist / private-IP rejection before the host-side fetch runs. From an IDE/agent host that can reach RFC1918 or link-local addresses, a model-chosen URL (or open redirect) is classic SSRF-shaped egress.
Suggested change:
- Before
fetchFn, resolve and reject private/special-purpose/metadata destinations (and re-check redirect targets if the fetch follows redirects).
- Optional
allowedHosts / allowPrivateNetwork config for power users.
- Keep the existing permission prompt.
Severity: medium as missing SSRF egress control on an agent URL tool; mitigated somewhat by allowedWithPermission. No proof-of-concept.
Happy to send a focused PR if this direction is useful.
Static review of public source at commit
5522c6f44ca0. No traffic was sent to any Continue environment.The built-in “Read URL” tool delegates to
getUrlContextItems, which performs an unrestricted fetch:core/context/providers/URLContextProvider.ts:core/tools/implementations/fetchUrlContent.tsonly truncates length. Policy isallowedWithPermission, which helps for intentional calls, but there is still no allowlist / private-IP rejection before the host-sidefetchruns. From an IDE/agent host that can reach RFC1918 or link-local addresses, a model-chosen URL (or open redirect) is classic SSRF-shaped egress.Suggested change:
fetchFn, resolve and reject private/special-purpose/metadata destinations (and re-check redirect targets if the fetch follows redirects).allowedHosts/allowPrivateNetworkconfig for power users.Severity: medium as missing SSRF egress control on an agent URL tool; mitigated somewhat by
allowedWithPermission. No proof-of-concept.Happy to send a focused PR if this direction is useful.