Skip to content

fix(agent-server): block request-body injection into agent constructor options - #1939

Open
ulivz wants to merge 2 commits into
mainfrom
fix/agent-server-unauthenticated-rce
Open

fix(agent-server): block request-body injection into agent constructor options#1939
ulivz wants to merge 2 commits into
mainfrom
fix/agent-server-unauthenticated-rce

fix(agent-server): update test snapshots for default host and harden …

915d9b5
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL failed Aug 5, 2026 in 2s

1 new alert including 1 high severity security vulnerability

New alerts in code changed by this pull request

Security Alerts:

  • 1 high

See annotations below for details.

View all branch alerts.

Annotations

Check failure on line 168 in multimodal/tarko/shared-utils/src/session-agent-options.ts

See this annotation in the file changed.

Code scanning / CodeQL

Remote property injection High

A property name to write to depends on a
user-provided value
.
A property name to write to depends on a
user-provided value
.