Skip to content

[Bug]: Web server binds to 0.0.0.0 exposing read/write PTY sessions to network #19

Description

@ja-mf

The embedded HTTP/WebSocket server in src/web/server/server.ts calls Bun.serve() without specifying a hostname, defaulting to 0.0.0.0.

This exposes the API to all network interfaces, allowing for remote code execution by just nmap discovery, an attacker who can reach the host can:

  • List and read PTY session output (GET /api/sessions, GET /api/sessions/:id/buffer/*)
  • Send arbitrary input to running PTY sessions (POST /api/sessions/:id/input)
  • Kill sessions (DELETE /api/sessions/:id)
  • Spawn new processes via the API (POST /api/sessions)

Fix: Bind to 127.0.0.1 by default with configurable hostname support, can suggest a PR if needed, but this is a critical security issue that should be addressed ASAP.

Activity

  1. added
    bugSomething isn't working
    on Feb 6, 2026
  2. shekohex commented on Feb 6, 2026

    @shekohex
    Owner
  3. MBanucu commented on Feb 7, 2026

    @MBanucu
    Contributor

    @ja-mf does #21 fix your issue? I don't like IPv4. I want to use IPv6. I didn't test it but this should leave the IPv4 route free. In the beginning I was specifying 127.0.0.1 and sometimes it was occupying both IP routes and sometimes not. I hope that it works. The tests pass.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions