Skip to content

fix(insurance): decode errors echo uncapped vendor values via %q (prompt-injection / log flooding) #336

Description

@cristim

Found by the mcp #55 gate (LeanerCloud/cloud-commitments-mcp#55, comment on the PR).

Problem

pkg/insurance decoding errors echo the rejected vendor value with %q and no length cap (quote.go ~L459 and nearby enum/term/payment validators). A hostile or buggy vendor response can therefore put an arbitrarily long, attacker-chosen string (the gate measured >100KB per enum field, including prompt-injection text such as "IGNORE ALL PREVIOUS INSTRUCTIONS") into an error that consumers may print or return to an LLM. Control bytes are escaped by %q, but the 256-byte cap the contract applies elsewhere is not applied on the error path.

Fix

Cap and sanitize every vendor value interpolated into an error (same cleaner and 256-byte cap used for success-path strings), or stop echoing the value and name only the field. Add tests with a >256-byte, control-character-laden value in every validated enum field (contract_term, payment_option, commitment types, provider, currency, product) asserting the error is bounded and sanitized; mutation-check each site.

Consumers

platform (internal/archera maps errors to fixed text: confirm no decode error passes through), cli (cmd/archera: confirm), mcp (tools/archera_comparison.go archeraError passes decode errors through: PR #55 must wrap/cap meanwhile). Needs a pkg pin bump per consumer after the fix.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions