Skip to content

fix: code scanning alert 5 in curl parser#91

Draft
jbeckwith-oai wants to merge 1 commit intomainfrom
codex/fix-codeql-alert-5-curl-comments
Draft

fix: code scanning alert 5 in curl parser#91
jbeckwith-oai wants to merge 1 commit intomainfrom
codex/fix-codeql-alert-5-curl-comments

Conversation

@jbeckwith-oai
Copy link
Copy Markdown
Contributor

@jbeckwith-oai jbeckwith-oai commented Apr 13, 2026

Summary

  • replace regex-based inline comment stripping with a small shell-aware scanner
  • preserve # characters inside quoted or escaped curl arguments
  • add parser regression tests for quoted, escaped, and comment cases

Root Cause

CodeQL flagged the greedy inline comment regex in parseCurl as polynomial-time on attacker-controlled input. It also stripped legitimate # characters from quoted headers and escaped data.

Validation

  • npm test -- src/parsers/curl.test.ts
  • npm run build

@jbeckwith-oai jbeckwith-oai changed the title [codex] Fix code scanning alert 5 in curl parser fix: code scanning alert 5 in curl parser Apr 13, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant