Skip to content

Web scraper SSRF: redirect targets not validated against private IPs #871

@bug-ops

Description

@bug-ops

Context

WebScrapeExecutor validates initial URL but allows 3 redirects. Redirect targets bypass SSRF protection.

Solution

Custom redirect policy that calls validate_url and resolve_and_validate on each redirect Location header.

Epic: #857 | Effort: S | Crate: zeph-tools

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority/mediumMedium prioritysecuritySecurity hardeningtoolsTool execution and MCP integration

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions