Pull requests / #992

#992 security-hardening

closed · @aelnaby · 0 コメント · GitHub で見る

Server & APINVIDIA / CUDAModels & quantsSecurity

本文

Security hardening across the API server, image fetching, MCP tools, archive extraction, model parsing, and native code.
Changes
Added request body size limits to prevent oversized requests.
Hardened vision image fetching against SSRF attacks.
Blocked local file access from image fetch requests.
Added checks for redirect targets, response size, and peer IP changes.
Restricted MCP tools to loopback access when no API key is configured.
Removed shell=True from process execution paths.
CORS now fails closed when ["*"] is used without an api_key.
Tightened trusted Origin validation.
Added safe ZIP extraction checks to prevent path traversal.
CUDA keyring files now use a private temporary directory.
Added allowlists for supported entrypoints.
Added overflow checks for GGUF, PLE, and index.txt parsing.
Added bounds validation to the native embedding path.
Updated security documentation and test_security.

Verification
serve.test_security: 22/22 passed
test_setup_risk: passed
Pins/config tests: passed
py_compile: passed

関連リンク

インストール・モデル・リリースへの站内リンク。