Repository navigation
fix: validate GIF and WEBP signatures as exact bytes - #703
Merged
testikun merged 4 commits intoOct 9, 2026
Merged
Conversation
Contributor
Author
|
@tt-a1i 请审核此 PR。最新提交已通过完整 GitHub CI,当前可合并;如有需要调整的地方,我会在原分支及时修复。 |
testikun
reviewed
Oct 9, 2026
testikun
approved these changes
Oct 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Fixes #697. ASCII decoding clears high bits, so corrupted GIF and RIFF/WEBP signatures pass Cursor input and Web HTTP image admission.
Value
Reject malformed image signatures before forwarding user input. This does not claim full image decoding or semantic validation.
Approach
Compare signature bytes exactly at both existing boundaries. Add actual Cursor transformation and Web HTTP admission regressions for valid signatures and each high-bit corruption. See docs/research/IMAGE_SIGNATURE_BYTES_2026-10-07.md.
Validation
Impact
User input: corrupted signatures rejected. Model context: valid images unchanged. Runtime: existing input boundaries only. Persistence/config: none. Compatibility: valid GIF87a/GIF89a/WEBP remain supported; PNG/JPEG unchanged.