Arbitrary Code Execution in @rspack/plugin-react-refresh prior to 1.6.0 via overlay.entry Manipulation
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 18/100
- Tipo di issue
- Bug
- Chiarezza
- Da chiarire
- Stato di attività
- Ferma
- Stack tecnologico
- react, typescript
Direzione di ricerca
Start by reviewing package/package/dist/sockets/WDSSocket.js line 51 and the related getSocketUrlParts path, then compare them with the two provided PoCs. Reproduce the reported overlay.entry flows and determine whether the claimed code-execution behavior is demonstrated; done means a confirmed, reproducible finding with a defined remediation scope.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
hi, we are a security team. We found a vulnerability in your project.
Vulnerability Report: @rspack/plugin-react-refresh
Package Information
| Field | Value |
|---|---|
| Package Name | @rspack/plugin-react-refresh |
| Version | 1.6.0 |
| Vulnerability Type | Arbitrary Code Execution |
Vulnerability Details
EX0001: Code Execution
Verified Output: [CASE_ID=EX0001] [VULN_CMD] overlay.entry taint triggered error with marker
Taint Analysis:
The overlay.entry option flows through plugin configuration into WDSSocket.js initialization. When the socket connection is established, the entry path is used to construct the WebSocket client. The connection.onMessage handler at line 51 processes incoming data with JSON.parse, which could trigger code execution if the entry path influences the socket URL construction or message handling logic. The attacker-controlled entry string could be crafted to manipulate the WebSocket connection initialization.
Sink Location: package/package/dist/sockets/WDSSocket.js line 51
PoC Code:
const _pkg = await import(require.resolve('./package/package'));
const ReactRefreshPlugin = _pkg.default;
const plugin = new ReactRefreshPlugin({ overlay: { entry: 'TAINT_MARKER_ENTRY', sockIntegration: 'wds' } });
const mockCompiler = { hooks: { compilation: { tap: () => {} }, done: { tap: () => {} } }, options: { devServer: { hot: true } } };
plugin.apply(mockCompiler);
PoC File: poc_EX0001.js
EX0004: Code Execution
Verified Output: [CASE_ID=EX0004] [VULN_CMD] overlay.entry query taint triggered error with marker
Taint Analysis:
The overlay.entry option with query parameters flows into the WDSSocket initialization. The resourceQuery parameter is processed by getSocketUrlParts (line 49) to construct the WebSocket URL. This query string influences the connection object creation (line 50) and the subsequent onMessage handler setup (line 51). If the query parameters are not properly sanitized, they could manipulate the message handling logic where JSON.parse is called on incoming data, potentially leading to prototype pollution or code execution through crafted WebSocket messages.
Sink Location: package/package/dist/sockets/WDSSocket.js line 51
PoC Code:
const _pkg = await import(require.resolve('./package/package'));
const ReactRefreshPlugin = _pkg.default;
const plugin = new ReactRefreshPlugin({ overlay: { entry: 'webpack-dev-server/client?TAINT_MARKER_QUERY', sockIntegration: 'wds' } });
const mockCompiler = { hooks: { compilation: { tap: () => {} }, done: { tap: () => {} } }, options: { devServer: { hot: true } } };
plugin.apply(mockCompiler);
PoC File: poc_EX0004.js
Affected Sinks
| File | Line | Type | Code Snippet |
|---|---|---|---|
package/package/dist/index.js |
14 | NO_HASOWN | for(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, { |
package/package/dist/index.js |
248 | DYNAMIC_PROP_WRITE | exports["default"] = __webpack_exports__["default"]; |
package/package/dist/index.js |
249 | NO_HASOWN | for(var __webpack_i__ in __webpack_exports__)if (-1 === [ |
package/package/dist/index.js |
252 | DYNAMIC_PROP_WRITE | ].indexOf(__webpack_i__)) exports[__webpack_i__] = __webpack_exports__[__webpack_i__]; |
package/package/dist/sockets/WHMEventSource.js |
5 | NO_HASOWN | for(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, { |
package/package/dist/sockets/WHMEventSource.js |
47 | NO_HASOWN | for(var __webpack_i__ in __webpack_exports__)if (-1 === [ |
package/package/dist/sockets/WHMEventSource.js |
49 | DYNAMIC_PROP_WRITE | ].indexOf(__webpack_i__)) exports[__webpack_i__] = __webpack_exports__[__webpack_i__]; |
package/package/dist/sockets/WDSSocket.js |
14 | NO_HASOWN | for(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, { |
package/package/dist/sockets/WDSSocket.js |
58 | NO_HASOWN | for(var __webpack_i__ in __webpack_exports__)if (-1 === [ |
package/package/dist/sockets/WDSSocket.js |
60 | DYNAMIC_PROP_WRITE | ].indexOf(__webpack_i__)) exports[__webpack_i__] = __webpack_exports__[__webpack_i__]; |
package/package/dist/sockets/utils/getSocketUrlParts.js |
14 | NO_HASOWN | for(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, { |
package/package/dist/sockets/utils/getSocketUrlParts.js |
46 | DYNAMIC_PROP_WRITE | parsedQuery[key] = value; |
package/package/dist/sockets/utils/getSocketUrlParts.js |
81 | DYNAMIC_PROP_WRITE | exports["default"] = __webpack_exports__["default"]; |
package/package/dist/sockets/utils/getSocketUrlParts.js |
82 | NO_HASOWN | for(var __webpack_i__ in __webpack_exports__)if (-1 === [ |
package/package/dist/sockets/utils/getSocketUrlParts.js |
84 | DYNAMIC_PROP_WRITE | ].indexOf(__webpack_i__)) exports[__webpack_i__] = __webpack_exports__[__webpack_i__]; |
package/package/dist/sockets/utils/getCurrentScriptSource.js |
5 | NO_HASOWN | for(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, { |
package/package/dist/sockets/utils/getCurrentScriptSource.js |
39 | DYNAMIC_PROP_WRITE | exports["default"] = __webpack_exports__["default"]; |
package/package/dist/sockets/utils/getCurrentScriptSource.js |
40 | NO_HASOWN | for(var __webpack_i__ in __webpack_exports__)if (-1 === [ |
package/package/dist/sockets/utils/getCurrentScriptSource.js |
42 | DYNAMIC_PROP_WRITE | ].indexOf(__webpack_i__)) exports[__webpack_i__] = __webpack_exports__[__webpack_i__]; |
package/package/dist/sockets/utils/getUrlFromParts.js |
5 | NO_HASOWN | for(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, { |
| ... | ... | ... | (47 more sinks) |
Remediation
- Validate all configuration options and callbacks before use
- Avoid passing untrusted functions or objects as configuration
- Use TypeScript strict typing to prevent unexpected function injection
- Review all entry points that accept user-controlled configuration objects
- Lingua principale
- TypeScript
- Stelle
- 20
- Fork
- 13
- Merge medio
- 3h 18m
- PR unite (30g)
- 3
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di rstackjs/rspack-plugin-react-refresh
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 38/100
-
Difficoltà 3/5 1-2 giorni Idoneità per principianti 52/100
-
Dependency DashboardAperta
Difficoltà 3/5 1-2 giorni Idoneità per principianti 35/100
Tutte le issue di rstackjs/rspack-plugin-react-refresh
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
Comfy-Org/ComfyUI_frontend#20346 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
decentralized-identity/didwebvh-ts#203 ·
I maintainer di solito rispondono entro 1 giorno
-
community first-timers-only good first issue hacktoberfest help wanted low hanging fruit up-for-grabs
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
lingdojo/kana-dojo#31791 · 1 commento · 5 reazioni ·
I maintainer di solito rispondono entro 1 giorno
-
Telegram webhook: line breaks lost since switch to rich messagesForse già presa @Kshot3000 l’ha presa oggi. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
I maintainer di solito rispondono entro 1 giorno
-
github_actions security
Difficoltà 2/5 1-3 ore Idoneità per principianti 75/100
I maintainer di solito rispondono entro 1 giorno