repo import --from fetches from a user-supplied URL with no address check.
internal/control/import.go (~79-90) allows http, https and git:// and calls gitutil.FetchMirror, which runs git with the daemon's full environment and follows redirects. Nothing resolves or checks the host, so any user can make the server fetch from loopback or private addresses. Mirrors and webhooks resolve, check (webhook.CheckAddrs) and pin since #279; import does not.
- Give import the same resolve, check and pin as mirror sync (
http.curloptResolve,http.followRedirects=false, a clean environment); decide whether git:// stays (it cannot be pinned the same way). - Update Threat-Model and Architecture/09-Controls (SSRF row) when it lands.
referenced in commit 539835bd23 by cmc: wiki: Known-Gaps keeps the open #298 row
2026-09-28 23:13 UTC