This release includes 5 security fixes for security teams reviewing exposed deployments.
Topics
+12 more
Affected surfaces
Summary
AI summarySecurity hardening closes five input-handling vulnerabilities in Chameleon.
Full changelog
Security hardening from an internal source audit. chameleon treats the repo it
analyzes as untrusted input; this closes five places where that input was handled
less carefully than the rest of the code already handles it. No remote code
execution and no default-reachable exploit was found. The fixes raise the floor
and make these paths consistent with chameleon's own safe_open and
sanitize_for_chameleon_context discipline.
Security
- The turn-end correctness judge no longer puts edited-file contents on the
process command line. The reviewer prompt embeds file diffs and was passed as
aclaude -p <prompt>argument, visible inps aux//proc/<pid>/cmdlineto
any local process for the spawn's lifetime. It is now fed on stdin. The judge
also drops secret-bearing files (.env,.ssh, credential dotfiles) before it
diffs them, so a secret a developer edits is never reconstructed into the
prompt; this reuses the forbidden-segment setsafe_openalready enforces, now
matched case-insensitively for case-insensitive filesystems. - The archetype summary is sanitized before it reaches the model. Free prose
from a committedarchetypes.jsonflowed into the model-callable
get_pattern_contextresponse withoutsanitize_for_chameleon_context, while
its sibling fields (idioms, witness) were sanitized. A crafted summary could
carry a context-escape token or a forged status header; it now passes through
the sanitizer like the rest. - The per-edit "Nearby files" listing is sanitized. Raw sibling filenames
were appended to the advisory<chameleon-context>block unsanitized, so a file
named with a control token (for example<|im_start|>), a bidi override, or a
forged[🦎 chameleon: ...]header could inject. The listing now goes through
the same sanitizer as every other repo-derived field. - The command log refuses symlinked paths. The exec-log directory and the
per-session log file are created and opened without following symlinks (lstat
beforemkdir,O_NOFOLLOWon the leaf), closing a symlink TOCTOU on a shared
TMPDIRwhere another local user could divert the log. The write fails open on
any error rather than crash the recorder hook. - The Ruby extractor runs from a neutral working directory with
RUBYOPTand
RUBYLIBscrubbed, matching the TypeScript extractor, so a poisoned interpreter
option cannot makerubyload repo code before the parse-onlyprism_dump.rb
runs.
Security Fixes
- The turn-end correctness judge no longer places edited-file contents on the process command line; it now feeds diffs via stdin and drops secret-bearing files (`.env`, `.ssh`) before diffing.
- The archetype summary is sanitized through `sanitize_for_chameleon_context` before reaching the model, preventing context-escape or forged header injection.
- The per-edit "Nearby files" listing is sanitized to prevent control token, bidi override, or forged `[🦎 chameleon: ...]` header injection.
- The command log refuses symlinked paths by using `lstat`, `mkdir` without following symlinks, and opening the log file with `O_NOFOLLOW`, closing a TOCTOU race in shared `TMPDIR`.
- The Ruby extractor runs from a neutral working directory with `RUBYOPT` and `RUBYLIB` scrubbed, matching the TypeScript extractor's isolation.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Chameleon
All releases →Beta — feedback welcome: [email protected]