fix(security): stop remote schedule runs from executing local veryfront.config.ts - #4376
Conversation
…nt.config.ts `veryfront schedule run <id> --remote` resolved credentials through resolveConfigWithAuth(), whose config-file lane dynamically imports veryfront.config.ts/.js from the working tree. A malicious repository could place side-effecting code in that file and have it execute with full CLI process permissions (env vars, local token store) the moment a logged-in user ran a remote schedule — breaking remote mode's boundary of running only source already pushed to Veryfront. Add resolveConfigWithAuthNoModule(), which resolves project identity from veryfront.json, environment variables, the project link, and the auth store without ever importing the module config, and use it in runRemoteSchedule(). The regression test plants a side-effecting veryfront.config.ts and asserts a remote run never executes it. Codex finding id: 7a8ed552e47081919bceca54313242c9 Claude-Session: https://claude.ai/code/session_01QfWNMiUhvWMKWi6BGfVdY3
There was a problem hiding this comment.
kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
|
You have reached your Codex usage limits for security reviews. Please try again later. |
|
Warning Review limit reachedNext included review available in 57 minutes. View limit detailsLimit details: You’ve used the included review currently available. You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Review configuration: ⚙️ Run configurationConfiguration used: Repository UI Review profile: CHILL Plan: Team Run ID: 📒 Files selected for processing (6)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
📦 Client bundle boundary
A server module in a client graph aborts hydration in the browser. New leaks fail CI; known leaks are tracked in |
|
Note Automatic reviews are paused because your trial's included automatic processing has been used for this period. Upgrade now, or comment "Gitar review" to run a review anytime. Code Review ✅ ApprovedFixes a remote code execution vulnerability where OptionsDisplay: compact → Showing less information. Comment with these commands to change the behavior for this request:
Important Your trial ends in 6 days — upgrade now to keep code review, CI analysis, auto-apply, custom automations, and more. Was this helpful? React with 👍 / 👎 | Gitar |
Code review: 90/100 — clean, well-scoped fix for a real RCE-via-config vulnerabilitySummary: Correctly closes the arbitrary-code-execution gap in Strengths:
Minor suggestions (non-blocking):
Nothing here blocks merge; the fix does what it claims, the test evidence is credible, and the diff is easy to reason about. Generated by Claude Code |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 16accc8cf5
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
…t reference Remote schedule runs no longer import veryfront.config.ts/.js. That left a checkout whose projectSlug is declared only in the module config with no environment reference, veryfront.json, or local project link falling through to inferProjectSlug, which derives a slug from package.json or the directory name. That silently resolves to a different project the token can reach, and a matching source trigger id there would start the wrong schedule. readConfigFileResolution now records that a module config exists but was deliberately not executed, and resolveConfigBase refuses to infer a reference in that case, pointing at VERYFRONT_PROJECT_SLUG, veryfront.json, or 'veryfront link' instead. Also swaps the schedule test's execution sentinel from a file the config writes plus a Deno.stat probe to an in-process global. The probe added a filesystem-read effect to a colocated unit whose semantic disposition does not declare one; the global proves the same thing without growing scripts/test/test-semantic-audit-migration.ts. Claude-Session: https://claude.ai/code/session_01QfWNMiUhvWMKWi6BGfVdY3
|
You have reached your Codex usage limits for security reviews. Please try again later. |
There was a problem hiding this comment.
kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
The three resolveConfigWithAuthNoModule tests called Deno.makeTempDir directly, which raised cli/shared/config.test.ts above its testing-front-door temp-dir baseline and failed ci (lint). Claude-Session: https://claude.ai/code/session_01QfWNMiUhvWMKWi6BGfVdY3
There was a problem hiding this comment.
kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
|
You have reached your Codex usage limits for security reviews. Please try again later. |
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
|
@codex review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
@codex review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
@codex review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
@codex review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
@codex review |
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 09f23218a4
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
There was a problem hiding this comment.
kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: abb77c768f
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
There was a problem hiding this comment.
kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
|
@codex review |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9b5a18f377
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 9b5a18f377
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
There was a problem hiding this comment.
kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
There was a problem hiding this comment.
kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
|
@codex review |
|
Codex Review: Didn't find any major issues. More of your lovely PRs please. Reviewed commit: ℹ️ About Codex in GitHubCodex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback". |
There was a problem hiding this comment.
kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: a51fbb4cc1
ℹ️ About Codex in GitHub
Codex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback".
|
@codex review |
|
Codex Review: Didn't find any major issues. Breezy! Reviewed commit: ℹ️ About Codex in GitHubCodex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback". |
There was a problem hiding this comment.
kojiwakayama has reached the 50-credit limit for trial accounts. To continue receiving code reviews, upgrade your plan.
|
@codex review |
|
Codex Review: Didn't find any major issues. Chef's kiss. Reviewed commit: ℹ️ About Codex in GitHubCodex has been enabled to automatically review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. When you sign up for Codex through ChatGPT, Codex can also answer questions or update the PR, like "@codex address that feedback". |
|



Summary
veryfront schedule run <id> --remoteis documented to run only source already pushed to Veryfront, but it resolved credentials viaresolveConfigWithAuth(), whose config-file lane doesawait import("file://.../veryfront.config.ts")(then.js) from the working tree, with import errors merely debug-logged. A malicious repository can therefore place side-effecting code inveryfront.config.tsand get arbitrary code execution with full CLI process permissions — able to read and exfiltrate environment variables or the local Veryfront token store — as soon as a logged-in user runs a remote schedule inside the checkout. Introduced in 18dd56f (#3119); later hardening passes (#3306, #4026) left the dynamic import on the remote path.Codex finding id:
7a8ed552e47081919bceca54313242c9(severity: medium).Fix
cli/shared/config.ts: thread anallowModuleConfigExecutionflag through the config resolver; when disabled,readConfigFileResolution()skips theveryfront.config.ts/.jsdynamic-import lane entirely. Project identity then comes only fromveryfront.json, environment variables, the local project link, or project-file inference. Exported asresolveConfigWithAuthNoModule(); all existing resolvers keep their current behavior.cli/commands/schedule/handler.ts:runRemoteSchedule()now usesresolveConfigWithAuthNoModule(), so the remote path never executes local repository code.Test evidence
cli/commands/schedule/handler.test.ts: the fixtureveryfront.config.tsnow writes a sentinel file and exports a competingprojectSlug, and the test asserts the sentinel is never created andveryfront.json's slug wins. Verified the test FAILS against the unfixed source (sentinel created) and passes with the fix.deno task test:file cli/commands/schedule/handler.test.ts— 4 passed (32 steps), 0 failed.deno task test:file cli/shared/config.test.ts— 6 passed (40 steps), 0 failed.deno check cli/main.ts,deno fmt --checkon touched files,deno linton touched files,deno task lint:style,lint:anti-slop,lint:cli-boundary— all clean.https://claude.ai/code/session_01QfWNMiUhvWMKWi6BGfVdY3