Skip to content

fix(security): stop remote schedule runs from executing local veryfront.config.ts - #4376

Merged
kojiwakayama merged 9 commits into
mainfrom
security/finding-62-remote-schedule-config-exec
Sep 3, 2026
Merged

kojiwakayama merged 9 commits into
mainfrom
security/finding-62-remote-schedule-config-exec

Conversation

@kojiwakayama

Copy link
Copy Markdown
Contributor

Summary

veryfront schedule run <id> --remote is documented to run only source already pushed to Veryfront, but it resolved credentials via resolveConfigWithAuth(), whose config-file lane does await import("file://.../veryfront.config.ts") (then .js) from the working tree, with import errors merely debug-logged. A malicious repository can therefore place side-effecting code in veryfront.config.ts and get arbitrary code execution with full CLI process permissions — able to read and exfiltrate environment variables or the local Veryfront token store — as soon as a logged-in user runs a remote schedule inside the checkout. Introduced in 18dd56f (#3119); later hardening passes (#3306, #4026) left the dynamic import on the remote path.

Codex finding id: 7a8ed552e47081919bceca54313242c9 (severity: medium).

Fix

  • cli/shared/config.ts: thread an allowModuleConfigExecution flag through the config resolver; when disabled, readConfigFileResolution() skips the veryfront.config.ts/.js dynamic-import lane entirely. Project identity then comes only from veryfront.json, environment variables, the local project link, or project-file inference. Exported as resolveConfigWithAuthNoModule(); all existing resolvers keep their current behavior.
  • cli/commands/schedule/handler.ts: runRemoteSchedule() now uses resolveConfigWithAuthNoModule(), so the remote path never executes local repository code.

Test evidence

  • Extended the "runs a pushed schedule without importing local runtime source" test in cli/commands/schedule/handler.test.ts: the fixture veryfront.config.ts now writes a sentinel file and exports a competing projectSlug, and the test asserts the sentinel is never created and veryfront.json's slug wins. Verified the test FAILS against the unfixed source (sentinel created) and passes with the fix.
  • deno task test:file cli/commands/schedule/handler.test.ts — 4 passed (32 steps), 0 failed.
  • deno task test:file cli/shared/config.test.ts — 6 passed (40 steps), 0 failed.
  • deno check cli/main.ts, deno fmt --check on touched files, deno lint on touched files, deno task lint:style, lint:anti-slop, lint:cli-boundary — all clean.

https://claude.ai/code/session_01QfWNMiUhvWMKWi6BGfVdY3

…nt.config.ts

`veryfront schedule run <id> --remote` resolved credentials through
resolveConfigWithAuth(), whose config-file lane dynamically imports
veryfront.config.ts/.js from the working tree. A malicious repository
could place side-effecting code in that file and have it execute with
full CLI process permissions (env vars, local token store) the moment a
logged-in user ran a remote schedule — breaking remote mode's boundary
of running only source already pushed to Veryfront.

Add resolveConfigWithAuthNoModule(), which resolves project identity
from veryfront.json, environment variables, the project link, and the
auth store without ever importing the module config, and use it in
runRemoteSchedule(). The regression test plants a side-effecting
veryfront.config.ts and asserts a remote run never executes it.

Codex finding id: 7a8ed552e47081919bceca54313242c9

Claude-Session: https://claude.ai/code/session_01QfWNMiUhvWMKWi6BGfVdY3

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

@coderabbitai

coderabbitai Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

Next included review available in 57 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Team

Run ID: d8a19bdf-24b9-465a-82ca-73fa1e64c68b

📥 Commits

Reviewing files that changed from the base of the PR and between f476d1b and b1ca982.

📒 Files selected for processing (6)
  • cli/commands/schedule/command-help.ts
  • cli/commands/schedule/handler.test.ts
  • cli/commands/schedule/handler.ts
  • cli/shared/config.test.ts
  • cli/shared/config.ts
  • docs/concepts/schedule.md

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-03T07:07:21.621752Z 09f2321 New commits
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@github-actions

github-actions Bot commented Sep 2, 2026 •

Copy link
Copy Markdown

📦 Client bundle boundary

Entrypoint Modules Source size Server leaks
src/index.client.ts 288 2272 KiB ✅ 0

A server module in a client graph aborts hydration in the browser. New leaks fail CI; known leaks are tracked in scripts/lint/client-bundle-baseline.json to burn down.

@gitar-bot

gitar-bot Bot commented Sep 2, 2026

Copy link
Copy Markdown

Note

Automatic reviews are paused because your trial's included automatic processing has been used for this period. Upgrade now, or comment "Gitar review" to run a review anytime.
Learn more

Code Review ✅ Approved

Fixes a remote code execution vulnerability where veryfront schedule run <id> --remote would execute local veryfront.config.ts despite being documented to run only pushed source. Introduces allowModuleConfigExecution flag to skip dynamic import of config files on remote paths, with resolveConfigWithAuthNoModule() used by remote schedule execution. Project identity falls back to veryfront.json, environment variables, or local project link. Test coverage confirms the sentinel file is never created and veryfront.json's configuration takes precedence. No issues found.

Options

Display: compact → Showing less information.

Comment with these commands to change the behavior for this request:

Compact
gitar display:verbose         

Important

Your trial ends in 6 days — upgrade now to keep code review, CI analysis, auto-apply, custom automations, and more.

Was this helpful? React with 👍 / 👎 | Gitar

Copy link
Copy Markdown
Contributor

Code review: 90/100 — clean, well-scoped fix for a real RCE-via-config vulnerability

Summary: Correctly closes the arbitrary-code-execution gap in veryfront schedule run --remote by gating the veryfront.config.ts/.js dynamic-import lane behind an allowModuleConfigExecution flag, defaulted true everywhere except the new resolveConfigWithAuthNoModule() used on the remote path.

Strengths:

  • Root-caused correctly: the vulnerability was that resolveConfigWithAuth()'s config-file lane does a dynamic import("file://…") of a working-tree file, so runRemoteSchedule() — a path documented to run only already-pushed source — was silently executing local repo code with full CLI process permissions (env vars, token store).
  • The fix threads the flag through cleanly (readConfigFileResolution → resolveConfigBase → createConfigResolver) without touching behavior for any of the other ~10 call sites of resolveConfigWithAuth/resolveConfig, and confirmed only one config-resolution call exists in schedule/handler.ts, so the whole remote path is covered.
  • Regression test is strong: it plants a veryfront.config.ts that both writes a sentinel file and exports a competing projectSlug, then asserts the sentinel is never created, the request sequence uses veryfront.json's slug/token, and exitCode === 0 (i.e., the fix doesn't break the legitimate remote-run flow). The PR description states this test was verified to fail pre-fix and pass post-fix.
  • Comments at each layer explain why (not just what), which matters for a security-sensitive code path future editors will touch.
  • Correctly scoped/minimal — no unrelated refactoring bundled in.

Minor suggestions (non-blocking):

  • No direct unit test in cli/shared/config.test.ts for resolveConfigWithAuthNoModule/the allowModuleConfigExecution flag itself — coverage currently comes only indirectly through the schedule/handler.test.ts integration test. A colocated unit test (e.g., config.ts present + flag disabled → module value ignored, veryfront.json still merged) would make the guarantee easier to verify in isolation and harder to regress via unrelated changes to the schedule handler.
  • Worth double-checking whether any other current or future "remote-mode" command (or a later --remote flag added elsewhere) should also default to resolveConfigWithAuthNoModule() rather than relying on each call site remembering to opt in — an allowlist-by-default (allowModuleConfigExecution defaulting false for anything not proven local-only) might be more robust long-term than the current opt-out default, though I recognize that's a larger behavioral change than this PR's scope.

Nothing here blocks merge; the fix does what it claims, the test evidence is credible, and the diff is easy to reason about.


Generated by Claude Code

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 16accc8cf5

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread cli/commands/schedule/handler.ts
@kwakayama kwakayama added the needs-human-input Maintainer action required label Sep 2, 2026
…t reference

Remote schedule runs no longer import veryfront.config.ts/.js. That left a
checkout whose projectSlug is declared only in the module config with no
environment reference, veryfront.json, or local project link falling through
to inferProjectSlug, which derives a slug from package.json or the directory
name. That silently resolves to a different project the token can reach, and
a matching source trigger id there would start the wrong schedule.

readConfigFileResolution now records that a module config exists but was
deliberately not executed, and resolveConfigBase refuses to infer a reference
in that case, pointing at VERYFRONT_PROJECT_SLUG, veryfront.json, or
'veryfront link' instead.

Also swaps the schedule test's execution sentinel from a file the config
writes plus a Deno.stat probe to an in-process global. The probe added a
filesystem-read effect to a colocated unit whose semantic disposition does
not declare one; the global proves the same thing without growing
scripts/test/test-semantic-audit-migration.ts.

Claude-Session: https://claude.ai/code/session_01QfWNMiUhvWMKWi6BGfVdY3
@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

The three resolveConfigWithAuthNoModule tests called Deno.makeTempDir
directly, which raised cli/shared/config.test.ts above its
testing-front-door temp-dir baseline and failed ci (lint).

Claude-Session: https://claude.ai/code/session_01QfWNMiUhvWMKWi6BGfVdY3

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for security reviews. Please try again later.

@codecov

codecov Bot commented Sep 3, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@kwakayama

Copy link
Copy Markdown
Contributor

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@kwakayama

Copy link
Copy Markdown
Contributor

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@kwakayama

Copy link
Copy Markdown
Contributor

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@kwakayama

Copy link
Copy Markdown
Contributor

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@kwakayama

Copy link
Copy Markdown
Contributor

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.

@kwakayama

Copy link
Copy Markdown
Contributor

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 09f23218a4

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread cli/shared/config.ts

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: abb77c768f

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread cli/shared/config.ts Outdated
Comment thread cli/shared/config.ts

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9b5a18f377

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread cli/commands/schedule/command-help.ts Outdated

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 9b5a18f377

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread cli/shared/config.ts Outdated

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. More of your lovely PRs please.

Reviewed commit: 9e82055818

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: a51fbb4cc1

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

Comment thread cli/commands/schedule/command-help.ts
@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Breezy!

Reviewed commit: a51fbb4cc1

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

@greptile-apps greptile-apps Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.

@github-actions

github-actions Bot commented Sep 3, 2026

Copy link
Copy Markdown

@codex review

@chatgpt-codex-connector

Copy link
Copy Markdown

Codex Review: Didn't find any major issues. Chef's kiss.

Reviewed commit: b1ca982de0

ℹ️ About Codex in GitHub

Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".

@sonarqubecloud

sonarqubecloud Bot commented Sep 3, 2026

Copy link
Copy Markdown

@kojiwakayama
kojiwakayama added this pull request to the merge queue Sep 3, 2026
Merged via the queue into main with commit 3885678 Sep 3, 2026
56 checks passed
@kojiwakayama
kojiwakayama deleted the security/finding-62-remote-schedule-config-exec branch September 3, 2026 22:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

needs-human-input Maintainer action required

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants