A security patch release for the 0.75 line. It carries one hardening change and nothing else; everything merged on main since 0.75.0 ships in the next minor release.
What's New
- Outbound endpoint checks refuse private IP literals on every scheme.
soup data generate --api-base, the vLLM provider and the commands that use it, judge URLs insoup eval judge, eval-gate suites,soup ship --judge-model/eval.ship.judge_model,training.online_dpo_judge, and the Web UI chat proxy now refuse a private, link-local or reserved IP literal overhttpsas well ashttp. Loopback still works; address a server on your network by its hostname.training.online_dpo_judgeis checked when soup.yaml loads, not only when the trainer starts. http://0.0.0.0is no longer treated as local bysoup data generate --api-baseand the Web UI chat proxy; uselocalhostor127.0.0.1.100.64.0.0/10andfec0::/10are non-public for every check that already refused private addresses (webhooks, the OTLP endpoint, telemetry, hub endpoints over HTTP, andsoup ingest --pull, where--allow-private-hostadmits them).- Non-ASCII spellings of an address are classified as that address. An IP literal written with non-ASCII digits or label separators is read the way the HTTP client folds it to ASCII before it connects. This applies to every check above.
Fixed
soup shipchecks--judge-modelbefore it builds the base and tuned models. It used to load both and only then stop with a usage error.- The Web UI chat proxy answers 400, not 500, for an endpoint URL that does not parse.
Install / Upgrade
pip install -U "soup-cli==0.75.2"
# or
pipx upgrade soup-cliSecurity
- Outbound endpoint validation (GHSA-9f49-hqpf-c849). Upgrade to 0.75.2. Until then, do not run an untrusted soup.yaml, eval-gate suite or
.canpackage that setsjudge_model,online_dpo_judgeoreval.ship.judge_model, and keepsoup uibound to loopback with its token private.
Known Limitations
- Hostnames are not resolved: a hostname that resolves to a private address is still accepted, as by every other endpoint check in Soup.
HF_ENDPOINTand the hub endpoint variables refuse private IP literals over plain HTTP only; they come from the operator's environment.- There is no opt-in for a private TLS endpoint addressed by an IP literal; use a hostname.
- The checks are found by their shape, so a new outbound call could skip them; a ratchet over every outbound call site is #1547.
- Loopback spellings differ between settings:
http://[::1]passes the judge and vLLM checks but not eval-gate suites,soup shipor the online-DPO trainer (#1548). - The refusal names no remedy, and
http://0.0.0.0gets only the generic HTTPS message (#1549). - IP-literal parsing depends on the platform's
inet_atonand, for 6to4 / NAT64 / Teredo addresses, on the interpreter'sipaddresstables (#1550).
Contributors
- @abdugafforov-bobur reported that the outbound endpoint checks accepted an
https://URL naming a private IP literal, with a clear reproduction.
The same fix is on main as #1527.