laststance / laststance/gitbox
x-forwarded-for first-IP spoofing on Vercel
Nobody has claimed this yet.
- Dominant language
- TypeScript
- Stars
- 5
- Forks
- 2
- Avg merge
- 6h 9m
- Merged PRs (30d)
- 2
Description
Summary
getForwardedClientIp takes split(',')[0], which on Vercel can be attacker-controlled.
Source
P2 follow-up from /ship adversarial review of PR #176 (silent GitHub token refresh).
Details
On Vercel, x-forwarded-for is appended to (not replaced), so the first hop is the client-controllable value. Bypass is rate-limit-only and requires authenticated session, but it still defeats per-IP throttling.
Fix
Switch to x-real-ip (Vercel-set) or read the LAST entry of x-forwarded-for.
Acceptance
- IP extraction uses trusted edge-set header
- Tests cover spoofed
x-forwarded-forchains - No rate-limit bypass via header injection
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
The entry point is getForwardedClientIp; first inspect how it handles x-forwarded-for and the Vercel x-real-ip option. Add tests for spoofed x-forwarded-for chains and verify that IP extraction uses the trusted value without allowing a rate-limit bypass.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- typescript
- Domain
- backend-api-design, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 58/100