Waleed ccc2ec9507 fix(file-parsers): guard .doc uploads against zip-bomb memory exhaustion (#6166)
* fix(file-parsers): guard .doc uploads against zip-bomb memory exhaustion

DocParser handed the raw upload straight to officeparser and then mammoth,
both of which inflate every ZIP entry into memory before any app-level size
cap applies. The extension is only a routing hint, so a bomb-bearing OOXML
archive renamed to .doc selected the one parser that skipped the guard its
docx/pptx/xlsx siblings all call.

Adds assertOoxmlArchiveWithinLimits to DocParser.parseBuffer, and centrally
in file-parsers parseBuffer so a future parser cannot silently opt out. The
guard reads the central directory's declared sizes without decompressing,
and no-ops for non-ZIP buffers, so legacy OLE .doc files are unaffected.

* fix(file-parsers): verify actual inflation, not just declared ZIP sizes

The declared uncompressed sizes in a ZIP central directory are attacker-
controlled, so a bomb can under-report them and pass the size and ratio
checks untouched. officeparser and mammoth only detect the mismatch after
inflating the entry in full: a 498 KB archive declaring 1000 bytes per entry
drove 559 MB resident through the .doc parser and 538 MB through .docx, then
failed. SheetJS and officeparser reject the container earlier, so xlsx/pptx
were not affected, but doc and docx both were.

Each entry is now inflated during verification under a maxOutputLength bound
equal to the size it declared. Node's zlib aborts the moment output would
exceed that bound, so a lying entry costs only its declared size and the
inflated bytes are discarded immediately; both bomb variants now reject at
+0 MB across every extension. Stored entries are checked against their own
compressed size, and unsupported compression methods fail closed.

Verification walks the contiguous run of central-directory records rather
than the EOCD's declared entry count, since that run is what a decompression
library allocates per entry — a lied-down count must not hide an entry from
verification.

Cost is ~0.45 ms per MB of uncompressed content (22 ms for a 50 MB archive),
against parse times an order of magnitude larger. All 17 real Word-produced
.docx fixtures in mammoth's test data are still accepted.

* fix(file-parsers): require central and local ZIP headers to agree

The parsers disagree about which header to trust. JSZip skips the local
header outright and decompresses using the central directory's method, while
SheetJS's parse_local_file switches on the local header's method and inflates
from there. An entry claiming STORED centrally and DEFLATE locally therefore
took the guard's stored branch, skipping bounded inflation, and was still
expanded downstream — a 398 KB archive hiding a 400 MB deflate payload.

Verification now rejects any entry whose two headers disagree on compression
method, and on declared sizes when the local header carries them (the
data-descriptor flag and ZIP64 sentinels legitimately omit them, and those
entries stay covered by the bounded inflate).

Caught by Greptile review. All 17 real Word-produced .docx fixtures in
mammoth's test data are still accepted.

* fix(file-parsers): charge hidden central-directory entries against the cap

sumDeclaredUncompressedSize walked only the entry count the EOCD declares,
while verification walks the contiguous run of records. JSZip's readCentralDir
loops on the record signature and keeps every entry it finds — a count
mismatch is explicitly not an error there — so an archive that under-reported
its count could hide honestly-large entries from the total-size cap and still
have the parser expand them.

The sum now walks the same contiguous run as the verification pass and
readZipCentralDirectoryStats, and fails closed when the run is shorter than
the declared count.

Caught by Cursor Bugbot review.
2026-08-01 17:30:23 -07:00

Sim.ai Documentation Slack X

Ask DeepWiki Set Up with Cursor

Sim — Integrate, Context, Build, and Monitor AI agents

A workspace to build, deploy and manage AI agents and workflows.

Quickstart

Cloud-hosted: sim.ai

Open sim.ai

Self-hosted

git clone https://github.com/simstudioai/sim.git && cd sim
bun run setup

Open http://localhost:3000

The Sim platform — chat on the left, the visual workflow builder on the right

Capabilities

  • Connect 1,000+ integrations and every major LLM
  • Add Slack, Notion, HubSpot, Salesforce, databases, and more
  • Build agents visually, conversationally, or with code
  • Ingest files, knowledge bases, and structured table data
  • Monitor runs, logs, schedules, and workflow activity

One workspace, every surface

Chat and workflows are just the start — tables, files, knowledge, and scheduled tasks all live in the same workspace.

Tables in Sim — structured data your agents can query

Tables — a database, built in

Files in Sim — documents for your team and every agent

Files — one store for your team and every agent

Knowledge bases in Sim — synced docs your agents can search

Knowledge — your agents' memory

Scheduled tasks in Sim — recurring agent runs on a calendar

Scheduled tasks — runs on your schedule

Self-hosting

Requirements: Bun and Docker.

bun run setup is an interactive wizard: it provisions the database, generates secrets, writes your .env files, connects a Chat API key, and starts Sim the way you choose:

  • Local dev — run from source to contribute or hack on Sim
  • Docker Compose — a self-contained instance for testing self-hosting
  • Kubernetes (Helm) — deploy to a local cluster

When it finishes, open http://localhost:3000.

Manage your install with bun run sim:

bun run sim start | stop | restart   # bring your install up / down / cycle
bun run sim status                    # what's installed and healthy
bun run sim logs                      # follow logs
bun run sim doctor                    # diagnose configuration problems
bun run sim down                      # remove containers (data kept)
bun run sim reset                     # archive .env and wipe managed data

sim detects how you're running (Docker Compose, local dev, or Kubernetes) and acts accordingly.

Prefer a bare sim? Run bun link once — but note sim lands in ~/.bun/bin, which Homebrew's bun doesn't add to your PATH, so you may need export PATH="$HOME/.bun/bin:$PATH" in your shell profile.

Sim also supports local models via Ollama and vLLM. See the self-hosting docs for details.

Chat API Keys

Chat is a Sim-managed service. bun run setup connects a Chat API key for you — sign in when it opens your browser and the key is stored automatically. To view, create, or revoke keys later, go to sim.ai/selfhost/settings/chat-keys.

Environment Variables

See the environment variables reference for the full list, or apps/sim/.env.example for defaults.

Tech Stack

Next.js · Bun · PostgreSQL · Drizzle · Better Auth · Tailwind — and the rest of the stack

Contributing

We welcome contributions! Please see our Contributing Guide for details.

License

This project is licensed under the Apache License 2.0 - see the LICENSE file for details.

Built by the Sim team in San Francisco

Languages
TypeScript 77%
MDX 20.8%
JavaScript 1.9%
CSS 0.1%