by @LeSuisse Activity log
- Created automatic suggestion
-
@LeSuisse
removed
22 packages
- helm
- helm-ls
- helmfile
- helmsman
- helm-docs
- helmholtz
- helm-dashboard
- kubernetes-helm
- helmfile-wrapped
- terraform-providers.helm
- kubernetes-helmPlugins.helm-dt
- kubernetes-helmPlugins.helm-s3
- kubernetes-helmPlugins.helm-git
- kubernetes-helmPlugins.helm-diff
- kubernetes-helmPlugins.helm-schema
- terraform-providers.hashicorp_helm
- kubernetes-helmPlugins.helm-cm-push
- kubernetes-helmPlugins.helm-secrets
- kubernetes-helmPlugins.helm-unittest
- kubernetes-helmPlugins.helm-mapkubeapis
- vimPlugins.nvim-treesitter-parsers.helm
- vscode-extensions.tim-koehler.helm-intellisense
- @LeSuisse dismissed
LangSmith Studio has URL Parameter Injection Vulnerability that Enables Token Theft via Malicious baseUrl
Langchain Helm Charts are Helm charts for deploying Langchain applications on Kubernetes. Prior to langchain-ai/helm version 0.12.71, a URL parameter injection vulnerability existed in LangSmith Studio that could allow unauthorized access to user accounts through stolen authentication tokens. The vulnerability affected both LangSmith Cloud and self-hosted deployments. Authenticated LangSmith users who clicked on a specially crafted malicious link would have their bearer token, user ID, and workspace ID transmitted to an attacker-controlled server. With this stolen token, an attacker could impersonate the victim and access any LangSmith resources or perform any actions the user was authorized to perform within their workspace. The attack required social engineering (phishing, malicious links in emails or chat applications) to convince users to click the crafted URL. The stolen tokens expired after 5 minutes, though repeated attacks against the same user were possible if they could be convinced to click malicious links multiple times. The fix in version 0.12.71 implements validation requiring user-defined allowed origins for the baseUrl parameter, preventing tokens from being sent to unauthorized servers. No known workarounds are available. Self-hosted customers must upgrade to the patched version.
References
- https://github.com/langchain-ai/helm/security/advisories/GHSA-r8wq-jwgw-p74g x_refsource_CONFIRM
Affected products
- ==< 0.12.71
Ignored packages (22)
pkgs.helm
Free, cross-platform, polyphonic synthesizer
pkgs.helm-ls
Language server for Helm
pkgs.helmfile
Declarative spec for deploying Helm charts
pkgs.helmsman
Helm Charts (k8s applications) as Code tool
pkgs.helm-docs
Tool for automatically generating markdown documentation for Helm charts
pkgs.helmholtz
Time domain pitch tracker for Pure Data
pkgs.helm-dashboard
Simplified way of working with Helm
pkgs.kubernetes-helm
Package manager for kubernetes
pkgs.helmfile-wrapped
Declarative spec for deploying Helm charts
pkgs.terraform-providers.helm
None
pkgs.kubernetes-helmPlugins.helm-dt
Helm Distribution plugin is is a set of utilities and Helm Plugin for making offline work with Helm Charts easier
pkgs.kubernetes-helmPlugins.helm-s3
Helm plugin that allows to set up a chart repository using AWS S3
pkgs.kubernetes-helmPlugins.helm-git
Helm downloader plugin that provides GIT protocol support
pkgs.kubernetes-helmPlugins.helm-diff
Helm plugin that shows a diff
pkgs.kubernetes-helmPlugins.helm-schema
Helm plugin for generating values.schema.json from multiple values files
pkgs.terraform-providers.hashicorp_helm
None
pkgs.kubernetes-helmPlugins.helm-cm-push
Helm plugin to push chart package to ChartMuseum
pkgs.kubernetes-helmPlugins.helm-secrets
Helm plugin that helps manage secrets
pkgs.kubernetes-helmPlugins.helm-unittest
BDD styled unit test framework for Kubernetes Helm charts as a Helm plugin
pkgs.kubernetes-helmPlugins.helm-mapkubeapis
Helm plugin which maps deprecated or removed Kubernetes APIs in a release to supported APIs
pkgs.vimPlugins.nvim-treesitter-parsers.helm
None
-
nixos-unstable 0.0.0+rev=04270cd
- nixpkgs-unstable 0.0.0+rev=04270cd
- nixos-unstable-small 0.0.0+rev=04270cd