Review agent · Web & injection

Server-side request forgery (SSRF)

Checks whether a server-side request can be pointed at a host the attacker chooses.

hooks/fetch.py1url = body["callback_url"]2resp = requests.get(url,3 allow_redirects=True)4return resp.json()SSRFwhat this review answersDoes the request pick the target?Host and scheme allow-listed?Can it reach metadata or localhost?$ verdict REAL ISSUE$ fix allow-list hosts, block internal IPs▍

Illustrative example of how this agent reviews a finding.

Why this agent matters

SSRF turns your server into a proxy into your own network. On cloud hosts that often means the instance metadata endpoint and the credentials behind it — the path used in the 2019 Capital One breach. It has its own slot in the OWASP Top 10 (A10).

Scanners can see an outbound HTTP call but not whether its destination is fixed, allow-listed or user-controlled. This agent makes that call, and checks the defences that are easy to miss: redirects, DNS rebinding and internal address ranges.

What it checks

  • HTTP clients, URL fetchers, webhooks and file/URL loaders whose target comes from a request
  • Missing host and scheme allow-lists
  • Redirect following and DNS-rebinding exposure
  • Reachability of metadata (169.254.169.254), localhost and RFC 1918 ranges

When it marks a finding as a likely false positive

  • The URL is fixed in code or config
  • The destination is validated against an explicit allow-list

The fix it suggests

  • An allow-list of explicit hosts and schemes
  • Blocking internal and metadata ranges after DNS resolution
  • Disabling automatic redirects

Scope and limits

This agent validates findings reported by Semgrep, Gitleaks and Trivy; it doesn't hunt for new bugs on its own. A finding reaches it when its CWE or rule/path keywords match this vulnerability class. It sees only the minimal code around the finding, with secrets redacted, and returns a verdict with a confidence score, a plain-English explanation and a suggested patch.

Common questions

Why does SSRF matter more on cloud infrastructure?

Cloud instances expose a metadata service on an internal address that can return credentials. An SSRF that reaches it can escalate from one request to cloud account access.

Related agents

  • SQL injection — Decides whether attacker-controlled input actually reaches a SQL or NoSQL query unparameterized.
  • Cross-site scripting (XSS) — Checks whether untrusted data is rendered into HTML or JavaScript without contextual encoding.
  • Command & code injection — Checks whether user input reaches a shell, eval or template-evaluation sink.

See all 20 review agents → · Agent setup reviewer · How the pipeline works

Run the Server-side request forgery (SSRF) agent on your repository

100 free credits, no credit card. Every finding comes with a verdict and a fix.

Get started free