Found by the mcp #55 gate (LeanerCloud/cloud-commitments-mcp#55, comment on the PR).
Problem
pkg/insurance decoding errors echo the rejected vendor value with %q and no length cap (quote.go ~L459 and nearby enum/term/payment validators). A hostile or buggy vendor response can therefore put an arbitrarily long, attacker-chosen string (the gate measured >100KB per enum field, including prompt-injection text such as "IGNORE ALL PREVIOUS INSTRUCTIONS") into an error that consumers may print or return to an LLM. Control bytes are escaped by %q, but the 256-byte cap the contract applies elsewhere is not applied on the error path.
Fix
Cap and sanitize every vendor value interpolated into an error (same cleaner and 256-byte cap used for success-path strings), or stop echoing the value and name only the field. Add tests with a >256-byte, control-character-laden value in every validated enum field (contract_term, payment_option, commitment types, provider, currency, product) asserting the error is bounded and sanitized; mutation-check each site.
Consumers
platform (internal/archera maps errors to fixed text: confirm no decode error passes through), cli (cmd/archera: confirm), mcp (tools/archera_comparison.go archeraError passes decode errors through: PR #55 must wrap/cap meanwhile). Needs a pkg pin bump per consumer after the fix.
Found by the mcp #55 gate (LeanerCloud/cloud-commitments-mcp#55, comment on the PR).
Problem
pkg/insurance decoding errors echo the rejected vendor value with
%qand no length cap (quote.go ~L459 and nearby enum/term/payment validators). A hostile or buggy vendor response can therefore put an arbitrarily long, attacker-chosen string (the gate measured >100KB per enum field, including prompt-injection text such as "IGNORE ALL PREVIOUS INSTRUCTIONS") into an error that consumers may print or return to an LLM. Control bytes are escaped by %q, but the 256-byte cap the contract applies elsewhere is not applied on the error path.Fix
Cap and sanitize every vendor value interpolated into an error (same cleaner and 256-byte cap used for success-path strings), or stop echoing the value and name only the field. Add tests with a >256-byte, control-character-laden value in every validated enum field (contract_term, payment_option, commitment types, provider, currency, product) asserting the error is bounded and sanitized; mutation-check each site.
Consumers
platform (internal/archera maps errors to fixed text: confirm no decode error passes through), cli (cmd/archera: confirm), mcp (tools/archera_comparison.go archeraError passes decode errors through: PR #55 must wrap/cap meanwhile). Needs a pkg pin bump per consumer after the fix.