{"record":{"id":"8652d6275d5e36cb","repo":"JuliusBrussee/caveman","slug":"githubapp-request-path-escaped-configured-host","errorCode":null,"errorMessage":"githubapp: request path escaped configured host","messagePattern":"githubapp: request path escaped configured host","errorType":"validation","errorClass":null,"httpStatus":null,"severity":"error","filePath":"shared/platform/githubapp/githubapp.go","lineNumber":362,"sourceCode":"func (a *App) DoToken(ctx context.Context, token, method, path string, body any) (int, []byte, error) {\n\treturn a.do(ctx, \"Bearer \"+token, method, path, body)\n}\n\nfunc (a *App) do(ctx context.Context, authorization, method, path string, body any) (int, []byte, error) {\n\tif !strings.HasPrefix(path, \"/\") || strings.HasPrefix(path, \"//\") || strings.Contains(path, \"\\\\\") {\n\t\treturn 0, nil, fmt.Errorf(\"githubapp: request path must be a single-host absolute path\")\n\t}\n\tbase, err := url.Parse(a.baseURL)\n\tif err != nil || base.Scheme == \"\" || base.Host == \"\" || base.User != nil {\n\t\treturn 0, nil, fmt.Errorf(\"githubapp: invalid base URL\")\n\t}\n\trelative, err := url.ParseRequestURI(path)\n\tif err != nil || relative.IsAbs() || relative.Host != \"\" || relative.User != nil {\n\t\treturn 0, nil, fmt.Errorf(\"githubapp: invalid request path\")\n\t}\n\ttarget, err := url.Parse(a.baseURL + path)\n\tif err != nil || target.Scheme != base.Scheme || !strings.EqualFold(target.Host, base.Host) || target.User != nil {\n\t\treturn 0, nil, fmt.Errorf(\"githubapp: request path escaped configured host\")\n\t}\n\tvar reader io.Reader\n\tif body != nil {\n\t\tb, err := json.Marshal(body)\n\t\tif err != nil {\n\t\t\treturn 0, nil, fmt.Errorf(\"githubapp: marshal request: %w\", err)\n\t\t}\n\t\treader = bytes.NewReader(b)\n\t}\n\treq, err := http.NewRequestWithContext(ctx, method, target.String(), reader)\n\tif err != nil {\n\t\treturn 0, nil, fmt.Errorf(\"githubapp: build request: %w\", err)\n\t}\n\treq.Header.Set(\"Authorization\", authorization)\n\treq.Header.Set(\"Accept\", \"application/vnd.github+json\")\n\treq.Header.Set(\"X-GitHub-Api-Version\", \"2022-11-28\")\n\tif body != nil {\n\t\treq.Header.Set(\"Content-Type\", \"application/json\")","sourceCodeStart":344,"sourceCodeEnd":380,"githubUrl":"https://github.com/JuliusBrussee/caveman/blob/766dce6b1394ebb56a3090748d5a0240a5aefb36/shared/platform/githubapp/githubapp.go#L344-L380","documentation":"SSRF guard in do(): joining baseURL+path produced a target whose scheme/host differs from the configured base (case-insensitive host compare) or that carries user info — i.e. the path escaped the fixed GitHub host. This is the final backstop ensuring all egress stays on one SSRF-guarded host.","triggerScenarios":"Thrown at shared/platform/githubapp/githubapp.go:362 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Inspect the path for encoded characters (e.g. @, ../, %2F) that reinterpret the URL and escape them","Keep paths within /repos/..., /app/... style endpoints; never build URLs from raw user input"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"766dce6b1394ebb56a3090748d5a0240a5aefb36","analyzedAt":"2026-08-18T03:14:35.516Z","contentChangedAt":"2026-08-18T03:14:35.516Z","schemaVersion":2},"datasetVersion":"2026-09-14T05:17:10.506Z"}