Self-hosted automation targets often run on localhost or loopback
addresses, so keep blocking private/metadata hosts but stop blocking
localhost, 127.x.x.x, and .localhost names.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>
Add $axios to the VM sandbox with a request interceptor that blocks
non-http(s) URLs and common SSRF targets (localhost, private IPs,
link-local, and cloud metadata hosts). require('axios') and import
axios resolve to the same screened instance so scripts cannot bypass
URL screening.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>