From b181bd3414df7bc6a316ec29da160e8dfd2bcd1f Mon Sep 17 00:00:00 2001 From: Cursor Agent Date: Fri, 14 Aug 2026 05:01:45 +0000 Subject: [PATCH] fix(sandbox): allow localhost in axios URL screening Self-hosted automation targets often run on localhost or loopback addresses, so keep blocking private/metadata hosts but stop blocking localhost, 127.x.x.x, and .localhost names. Co-authored-by: Nasyarobby Putra --- script-sandbox.js | 10 ---------- 1 file changed, 10 deletions(-) diff --git a/script-sandbox.js b/script-sandbox.js index 06b9646..e565967 100644 --- a/script-sandbox.js +++ b/script-sandbox.js @@ -188,15 +188,6 @@ function createConsole(logger) { function isBlockedHostname(hostname) { const host = hostname.toLowerCase().replace(/\.$/, ""); - if ( - host === "localhost" || - host === "0.0.0.0" || - host === "[::]" || - host === "[::1]" || - host.endsWith(".localhost") - ) { - return true; - } if (host === "metadata.google.internal" || host === "metadata.goog") { return true; @@ -214,7 +205,6 @@ function isBlockedHostname(hostname) { const [a, b] = octets; if (a === 10) return true; - if (a === 127) return true; if (a === 0) return true; if (a === 169 && b === 254) return true; if (a === 172 && b >= 16 && b <= 31) return true;