Skip to content

Strip newlines at the workspace log sink - #73

Merged
ashwin-kondapalli merged 1 commit into
mainfrom
fix-log-injection
Oct 4, 2026
Merged

ashwin-kondapalli merged 1 commit into
mainfrom
fix-log-injection

Conversation

@ashwin-kondapalli

Copy link
Copy Markdown
Collaborator

Log-injection fix: applies the newline sanitizer inline at the console.error sink in the workspace 500 handler.

158/158 tests.

Apply the canonical newline sanitizer inline at console.error so no
user-influenced error text can forge log entries.
Comment thread src/workspace.ts
const csrf = randomBytes(32).toString("base64url"); const runs = new Map<string, WorkspaceRun>();
const assets = resolve(dirname(fileURLToPath(import.meta.url)), "../workspace-assets");
const server = createServer(async (req, res) => { securityHeaders(res); try { await route(req, res); } catch (error) { console.error("[MCP Rigor workspace] internal error:", messageOf(error)); json(res, 500, { error: { code: "MCP-WEB-500", message: "Internal server error" } }); } });
const server = createServer(async (req, res) => { securityHeaders(res); try { await route(req, res); } catch (error) { console.error("[MCP Rigor workspace] internal error:", messageOf(error).replace(/\r?\n/g, " ")); json(res, 500, { error: { code: "MCP-WEB-500", message: "Internal server error" } }); } });
@ashwin-kondapalli

Copy link
Copy Markdown
Collaborator Author

Logo
Checkmarx One – Scan Summary & Details – 9ba5efd2-15d1-4daf-941c-3518cd90d9da

Great job! No new security vulnerabilities introduced in this pull request


Communicate with Checkmarx by submitting a PR comment with @Checkmarx followed by one of the supported commands. Learn about the supported commands here.

@ashwin-kondapalli
ashwin-kondapalli merged commit 55c9b25 into main Oct 4, 2026
42 checks passed
@ashwin-kondapalli
ashwin-kondapalli deleted the fix-log-injection branch October 4, 2026 03:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants