Skip to content

fix(genie-ui): defeat DNS rebinding on the ws PTY trust boundary - #2621

Merged
namastex888 merged 1 commit into
devfrom
fix/genie-ui-ws-dns-rebinding
Jul 22, 2026
Merged

namastex888 merged 1 commit into
devfrom
fix/genie-ui-ws-dns-rebinding

Conversation

@namastex888

Copy link
Copy Markdown
Contributor

What

The genie-ui PTY WebSocket auth (verifyClient) trusted its same-origin branch (new URL(origin).host === host) unconditionally. Both Origin and Host are browser-set, so a DNS-rebinding attack (evil.com → 127.0.0.1) presents Origin === Host === evil.com:PORT and passed the check — letting a malicious page send MSG.INPUT frames that flow handleClientMsg → manager.write → proc.write() into a live login shell (RCE as the operator). The loopback bind is no defense because the browser itself is the loopback client.

Fix

The same-origin branch now additionally requires the real Host hostname to be a loopback identity (localhost / 127.0.0.1 / ::1). After a rebind the Host is still evil.com (non-loopback), so it falls through to the existing GENIE_UI_ALLOWED_ORIGINS allowlist and is rejected. The allowlist escape hatch for legitimate LAN/remote browsers is unchanged.

Tests

  • Named DNS-rebinding regression test (Origin === Host === evil.com → rejected) — permanently owns the scenario.
  • Inverted the prior accepts any LAN hostname test (which enshrined the hole) → non-loopback same-origin now rejected.
  • Added allowlist-accept and IPv6 [::1] loopback cases; retained cross-origin / mismatched-port / malformed / no-Origin cases.
  • bun test packages/genie-ui/server/index.test.ts → 10 pass / 0 fail. Biome + typecheck clean.

Provenance

Found by an ultracode review of PR #2619 (dev→main promotion). One confirmed HIGH; adversarially verified (rebinding closed, escape hatch intact, no parsing bypass — IP-normalization tricks fail closed, credential/fragment/subdomain smuggling all rejected). Reviewed post-fix by an independent reviewer: SHIP.

Rated HIGH not CRITICAL because genie-ui is private: true, unpublished, absent from the CLI dist bundle, and manually launched — vulnerable source shipped, but no always-on exposure. Landing before genie-ui is recommended to anyone or exposed as a product surface.

…inding

verifyClient trusted new URL(origin).host === host unconditionally. both
Origin and Host are browser-set, so DNS rebinding (evil.com -> 127.0.0.1)
presents Origin === Host === evil.com:PORT and passed the check, opening
MSG.INPUT -> proc.write() into a live login shell (RCE).

the same-origin branch now additionally requires the real Host hostname to
be a loopback identity; non-loopback hosts fall through to the existing
GENIE_UI_ALLOWED_ORIGINS allowlist. adds a named rebinding regression test,
inverts the old any-LAN-host test, and corrects the README trust-boundary
claim.

found by ultracode review of PR #2619.
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

1 similar comment
@gemini-code-assist

Copy link
Copy Markdown
Contributor

Caution

The consumer version of Gemini Code Assist on GitHub has been sunset. All code review activity has officially ceased.

@coderabbitai

coderabbitai Bot commented Jul 22, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro

Run ID: 09c93cb7-4ebf-491d-8970-ae842b869996

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/genie-ui-ws-dns-rebinding

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@namastex888
namastex888 merged commit b251fdb into dev Jul 22, 2026
12 of 18 checks passed
@automagik-genie
automagik-genie deleted the fix/genie-ui-ws-dns-rebinding branch September 25, 2026 04:50
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant