Pull requests / #992
#992 security-hardening
closed · @aelnaby · 0 评论 · 在 GitHub 查看
Server & APINVIDIA / CUDAModels & quantsSecurity
描述
Security hardening across the API server, image fetching, MCP tools, archive extraction, model parsing, and native code. Changes Added request body size limits to prevent oversized requests. Hardened vision image fetching against SSRF attacks. Blocked local file access from image fetch requests. Added checks for redirect targets, response size, and peer IP changes. Restricted MCP tools to loopback access when no API key is configured. Removed shell=True from process execution paths. CORS now fails closed when ["*"] is used without an api_key. Tightened trusted Origin validation. Added safe ZIP extraction checks to prevent path traversal. CUDA keyring files now use a private temporary directory. Added allowlists for supported entrypoints. Added overflow checks for GGUF, PLE, and index.txt parsing. Added bounds validation to the native embedding path. Updated security documentation and test_security. Verification serve.test_security: 22/22 passed test_setup_risk: passed Pins/config tests: passed py_compile: passed
站内延伸阅读
链到安装、模型与版本说明,便于 SEO/GEO,非官方 issue 正文。