Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Security: Multiple vulnerabilities found via Snyk Code Analysis (XSS, Path Traversal, ReDoS, Open Redirect)

オープン
#7,737 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

評価

難易度
5/5
見積もり時間
1週間以上
初心者へのやさしさ
25/100
issue の種類
バグ
明瞭さ
説明が足りない
活発さ
静か
技術スタック
node.js, typescript
領域
backend, security

調査の方向性

まず v4.112.0 付近の main branch に対して Snyk Code Analysis を再実行し、その後、src/node/routes/errors.ts、login.ts、vscode.ts、domainProxy.ts、index.ts、src/node/app.ts で報告された箇所を確認します。本番環境の検出結果と、テストファイルにある低重大度の検出結果を分け、各脆弱性を確認し、提案された緩和策を検討します。確認された本番環境の検出結果に対処し、スキャンでそれらが報告されなくなれば完了です。

索引モデルが issue の本文から書いたものです。

説明

bug security

Summary

Snyk Code Analysis identified 65 issues across 92 analyzed files in code-server. The High severity findings affect production deployments.

High Severity (7 issues)

Cross-site Scripting (XSS) — CWE-79, Score 807
  • src/node/routes/errors.ts line 56
  • src/node/routes/login.ts lines 68, 119

User-controlled input may be rendered without proper HTML escaping in error and login responses.

Path Traversal — CWE-23, Score 804
  • src/node/routes/vscode.ts lines 149, 219

User-supplied path components may allow reading files outside the intended directory.

Regular Expression Denial of Service (ReDoS) — CWE-400, Score 752
  • src/node/routes/domainProxy.ts line 46

A regex pattern may cause catastrophic backtracking with crafted input.

Medium Severity (14 issues)

Open Redirect — CWE-601, Score 557
  • src/node/routes/login.ts lines 62, 99
  • src/node/routes/index.ts line 94
Allocation of Resources Without Limits — CWE-770, Score 555
  • src/node/routes/errors.ts line 37
  • src/node/routes/vscode.ts line 213
Information Exposure via X-Powered-By — CWE-200, Score 554
  • src/node/app.ts line 70
Sensitive Cookie Without Secure/HttpOnly Flags — CWE-614/CWE-1004, Score 402
  • src/node/routes/login.ts line 96

Low Severity (44 issues)

Primarily in test files (hardcoded passwords, cleartext HTTP). Not production concerns.

Reproduction

Scanned with Snyk Code Analysis on code-server main branch (commit near v4.112.0).

Suggested Fixes

  • XSS: HTML-encode user input before rendering in error/login templates
  • Path Traversal: Resolve and validate paths against intended root directory
  • ReDoS: Simplify or replace the vulnerable regex pattern
  • Open Redirect: Validate redirect URLs against an allowlist
  • X-Powered-By: Disable with app.disable('x-powered-by')
  • Cookie flags: Add Secure and HttpOnly to session cookies

Happy to submit PRs for any of these if the team confirms the approach.

主要言語
TypeScript
スター
79.4k
フォーク
6.9k
平均マージ
2日 13時間
マージ済み PR(30日)
39

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

coder/code-server のほかの issue

coder/code-server の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。