Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Arbitrary Code Execution in @rspack/plugin-react-refresh prior to 1.6.0 via overlay.entry Manipulation

Abierto
#75 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
5/5
Tiempo estimado
Más de una semana
Aptitud para principiantes
18/100
Tipo de issue
Error
Claridad
Necesita aclaración
Estado de actividad
Estancado
Stack tecnológico
react, typescript

Línea de trabajo

Start by reviewing package/package/dist/sockets/WDSSocket.js line 51 and the related getSocketUrlParts path, then compare them with the two provided PoCs. Reproduce the reported overlay.entry flows and determine whether the claimed code-execution behavior is demonstrated; done means a confirmed, reproducible finding with a defined remediation scope.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

hi, we are a security team. We found a vulnerability in your project.

Vulnerability Report: @rspack/plugin-react-refresh

Package Information

Field Value
Package Name @rspack/plugin-react-refresh
Version 1.6.0
Vulnerability Type Arbitrary Code Execution

Vulnerability Details

EX0001: Code Execution

Verified Output: [CASE_ID=EX0001] [VULN_CMD] overlay.entry taint triggered error with marker

Taint Analysis:

The overlay.entry option flows through plugin configuration into WDSSocket.js initialization. When the socket connection is established, the entry path is used to construct the WebSocket client. The connection.onMessage handler at line 51 processes incoming data with JSON.parse, which could trigger code execution if the entry path influences the socket URL construction or message handling logic. The attacker-controlled entry string could be crafted to manipulate the WebSocket connection initialization.

Sink Location: package/package/dist/sockets/WDSSocket.js line 51

PoC Code:

const _pkg = await import(require.resolve('./package/package'));
const ReactRefreshPlugin = _pkg.default;
const plugin = new ReactRefreshPlugin({ overlay: { entry: 'TAINT_MARKER_ENTRY', sockIntegration: 'wds' } });
const mockCompiler = { hooks: { compilation: { tap: () => {} }, done: { tap: () => {} } }, options: { devServer: { hot: true } } };
plugin.apply(mockCompiler);

PoC File: poc_EX0001.js


EX0004: Code Execution

Verified Output: [CASE_ID=EX0004] [VULN_CMD] overlay.entry query taint triggered error with marker

Taint Analysis:

The overlay.entry option with query parameters flows into the WDSSocket initialization. The resourceQuery parameter is processed by getSocketUrlParts (line 49) to construct the WebSocket URL. This query string influences the connection object creation (line 50) and the subsequent onMessage handler setup (line 51). If the query parameters are not properly sanitized, they could manipulate the message handling logic where JSON.parse is called on incoming data, potentially leading to prototype pollution or code execution through crafted WebSocket messages.

Sink Location: package/package/dist/sockets/WDSSocket.js line 51

PoC Code:

const _pkg = await import(require.resolve('./package/package'));
const ReactRefreshPlugin = _pkg.default;
const plugin = new ReactRefreshPlugin({ overlay: { entry: 'webpack-dev-server/client?TAINT_MARKER_QUERY', sockIntegration: 'wds' } });
const mockCompiler = { hooks: { compilation: { tap: () => {} }, done: { tap: () => {} } }, options: { devServer: { hot: true } } };
plugin.apply(mockCompiler);

PoC File: poc_EX0004.js


Affected Sinks

File Line Type Code Snippet
package/package/dist/index.js 14 NO_HASOWN for(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, {
package/package/dist/index.js 248 DYNAMIC_PROP_WRITE exports["default"] = __webpack_exports__["default"];
package/package/dist/index.js 249 NO_HASOWN for(var __webpack_i__ in __webpack_exports__)if (-1 === [
package/package/dist/index.js 252 DYNAMIC_PROP_WRITE ].indexOf(__webpack_i__)) exports[__webpack_i__] = __webpack_exports__[__webpack_i__];
package/package/dist/sockets/WHMEventSource.js 5 NO_HASOWN for(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, {
package/package/dist/sockets/WHMEventSource.js 47 NO_HASOWN for(var __webpack_i__ in __webpack_exports__)if (-1 === [
package/package/dist/sockets/WHMEventSource.js 49 DYNAMIC_PROP_WRITE ].indexOf(__webpack_i__)) exports[__webpack_i__] = __webpack_exports__[__webpack_i__];
package/package/dist/sockets/WDSSocket.js 14 NO_HASOWN for(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, {
package/package/dist/sockets/WDSSocket.js 58 NO_HASOWN for(var __webpack_i__ in __webpack_exports__)if (-1 === [
package/package/dist/sockets/WDSSocket.js 60 DYNAMIC_PROP_WRITE ].indexOf(__webpack_i__)) exports[__webpack_i__] = __webpack_exports__[__webpack_i__];
package/package/dist/sockets/utils/getSocketUrlParts.js 14 NO_HASOWN for(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, {
package/package/dist/sockets/utils/getSocketUrlParts.js 46 DYNAMIC_PROP_WRITE parsedQuery[key] = value;
package/package/dist/sockets/utils/getSocketUrlParts.js 81 DYNAMIC_PROP_WRITE exports["default"] = __webpack_exports__["default"];
package/package/dist/sockets/utils/getSocketUrlParts.js 82 NO_HASOWN for(var __webpack_i__ in __webpack_exports__)if (-1 === [
package/package/dist/sockets/utils/getSocketUrlParts.js 84 DYNAMIC_PROP_WRITE ].indexOf(__webpack_i__)) exports[__webpack_i__] = __webpack_exports__[__webpack_i__];
package/package/dist/sockets/utils/getCurrentScriptSource.js 5 NO_HASOWN for(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, {
package/package/dist/sockets/utils/getCurrentScriptSource.js 39 DYNAMIC_PROP_WRITE exports["default"] = __webpack_exports__["default"];
package/package/dist/sockets/utils/getCurrentScriptSource.js 40 NO_HASOWN for(var __webpack_i__ in __webpack_exports__)if (-1 === [
package/package/dist/sockets/utils/getCurrentScriptSource.js 42 DYNAMIC_PROP_WRITE ].indexOf(__webpack_i__)) exports[__webpack_i__] = __webpack_exports__[__webpack_i__];
package/package/dist/sockets/utils/getUrlFromParts.js 5 NO_HASOWN for(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, {
... ... ... (47 more sinks)

Remediation

  • Validate all configuration options and callbacks before use
  • Avoid passing untrusted functions or objects as configuration
  • Use TypeScript strict typing to prevent unexpected function injection
  • Review all entry points that accept user-controlled configuration objects

Lenguaje dominante
TypeScript
Estrellas
20
Forks
13
Merge medio
2 h 55 min
PR fusionados (30 d)
6

Guía de contribución

No hay ninguna guía de contribución indexada para este repositorio

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de rstackjs/rspack-plugin-react-refresh

Todos los issues de rstackjs/rspack-plugin-react-refresh

Issues similares

Más issues de TypeScript

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.