api(arweave): GET /arweave/anchors has no visibility gate and leaks private-repo ref names and shas #500
Copy link
Copy link
Closed
Labels
crate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:securityVulnerability fix or hardeningVulnerability fix or hardeningsev:highMajor break or real security/trust risk, no easy workaroundMajor break or real security/trust risk, no easy workaroundsubsystem:apiNode REST API request/response surfaceNode REST API request/response surfacesubsystem:visibilityPath-scoped visibility and content withholdingPath-scoped visibility and content withholding
Description
Activity
- addedkind:securityVulnerability fix or hardeningVulnerability fix or hardeningsev:highMajor break or real security/trust risk, no easy workaroundMajor break or real security/trust risk, no easy workaroundsubsystem:apiNode REST API request/response surfaceNode REST API request/response surfacesubsystem:visibilityPath-scoped visibility and content withholdingPath-scoped visibility and content withholdingcrate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST API
on Oct 2, 2026
Metadata
Metadata
Assignees
Labels
crate:nodegitlawb-node — the serving node and REST APIgitlawb-node — the serving node and REST APIkind:securityVulnerability fix or hardeningVulnerability fix or hardeningsev:highMajor break or real security/trust risk, no easy workaroundMajor break or real security/trust risk, no easy workaroundsubsystem:apiNode REST API request/response surfaceNode REST API request/response surfacesubsystem:visibilityPath-scoped visibility and content withholdingPath-scoped visibility and content withholding
GET /api/v1/arweave/anchors(crates/gitlawb-node/src/api/arweave.rs:24-40,db/mod.rs:3836-3858) has no auth extractor and no visibility check. Sibling feeds (events.rs, stats, repo listings) gate every row per caller.Impact: anonymous callers get
repo,owner_did,ref_name,old_sha,new_shaand the Arweave/Irys tx id for anchors of private repos, which leaks branch names and commit tips.Repro:
GET /api/v1/arweave/anchors?repo=<owner-key>/<name>on a private repo returns 200 with ref names and shas.Fix: apply the same per-row visibility gate
events.rsuses (no existence leak), and add deny tests for an anonymous and a non-reader caller. Separate from #490 (negativelimit).Found in the Oct 2 2026 audit (A4) at bfc44f9.