Skip to content

[CodeScanning #136] go/request-forgery in pkg/llmproxy/auth/kiro/sso_oidc.go:208 #4

@KooshaPari

Description

@KooshaPari

Source alert: https://github.com/KooshaPari/cliproxyapi-plusplus/security/code-scanning/136

Rule:

  • ID: go/request-forgery
  • Description: Uncontrolled data used in network request
  • Severity: critical

Location:

  • Ref: refs/heads/main
  • File: pkg/llmproxy/auth/kiro/sso_oidc.go
  • Line: 208

Message:
The URL of this request depends on a user-provided value.

Scope:

  • Reproduce and confirm reachability
  • Implement fix with tests
  • Close code-scanning alert in GitHub

Metadata

Metadata

Assignees

No one assigned

    Labels

    code-scanningGitHub code scanning alert trackingcodeqlCodeQL alertsecuritySecurity issue

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions