Arbitrary Code Execution in @rspack/plugin-react-refresh prior to 1.6.0 via overlay.entry Manipulation
还没有人认领这个 Issue。
评估
- 难度
- 5/5
- 预计耗时
- 一周以上
- 新手友好度
- 18/100
- Issue 类型
- 缺陷
- 描述清晰度
- 需要澄清
- 活跃度
- 停滞
- 技术栈
- react, typescript
调研方向
Start by reviewing package/package/dist/sockets/WDSSocket.js line 51 and the related getSocketUrlParts path, then compare them with the two provided PoCs. Reproduce the reported overlay.entry flows and determine whether the claimed code-execution behavior is demonstrated; done means a confirmed, reproducible finding with a defined remediation scope.
由索引模型根据 Issue 内容生成。
描述
hi, we are a security team. We found a vulnerability in your project.
Vulnerability Report: @rspack/plugin-react-refresh
Package Information
| Field | Value |
|---|---|
| Package Name | @rspack/plugin-react-refresh |
| Version | 1.6.0 |
| Vulnerability Type | Arbitrary Code Execution |
Vulnerability Details
EX0001: Code Execution
Verified Output: [CASE_ID=EX0001] [VULN_CMD] overlay.entry taint triggered error with marker
Taint Analysis:
The overlay.entry option flows through plugin configuration into WDSSocket.js initialization. When the socket connection is established, the entry path is used to construct the WebSocket client. The connection.onMessage handler at line 51 processes incoming data with JSON.parse, which could trigger code execution if the entry path influences the socket URL construction or message handling logic. The attacker-controlled entry string could be crafted to manipulate the WebSocket connection initialization.
Sink Location: package/package/dist/sockets/WDSSocket.js line 51
PoC Code:
const _pkg = await import(require.resolve('./package/package'));
const ReactRefreshPlugin = _pkg.default;
const plugin = new ReactRefreshPlugin({ overlay: { entry: 'TAINT_MARKER_ENTRY', sockIntegration: 'wds' } });
const mockCompiler = { hooks: { compilation: { tap: () => {} }, done: { tap: () => {} } }, options: { devServer: { hot: true } } };
plugin.apply(mockCompiler);
PoC File: poc_EX0001.js
EX0004: Code Execution
Verified Output: [CASE_ID=EX0004] [VULN_CMD] overlay.entry query taint triggered error with marker
Taint Analysis:
The overlay.entry option with query parameters flows into the WDSSocket initialization. The resourceQuery parameter is processed by getSocketUrlParts (line 49) to construct the WebSocket URL. This query string influences the connection object creation (line 50) and the subsequent onMessage handler setup (line 51). If the query parameters are not properly sanitized, they could manipulate the message handling logic where JSON.parse is called on incoming data, potentially leading to prototype pollution or code execution through crafted WebSocket messages.
Sink Location: package/package/dist/sockets/WDSSocket.js line 51
PoC Code:
const _pkg = await import(require.resolve('./package/package'));
const ReactRefreshPlugin = _pkg.default;
const plugin = new ReactRefreshPlugin({ overlay: { entry: 'webpack-dev-server/client?TAINT_MARKER_QUERY', sockIntegration: 'wds' } });
const mockCompiler = { hooks: { compilation: { tap: () => {} }, done: { tap: () => {} } }, options: { devServer: { hot: true } } };
plugin.apply(mockCompiler);
PoC File: poc_EX0004.js
Affected Sinks
| File | Line | Type | Code Snippet |
|---|---|---|---|
package/package/dist/index.js |
14 | NO_HASOWN | for(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, { |
package/package/dist/index.js |
248 | DYNAMIC_PROP_WRITE | exports["default"] = __webpack_exports__["default"]; |
package/package/dist/index.js |
249 | NO_HASOWN | for(var __webpack_i__ in __webpack_exports__)if (-1 === [ |
package/package/dist/index.js |
252 | DYNAMIC_PROP_WRITE | ].indexOf(__webpack_i__)) exports[__webpack_i__] = __webpack_exports__[__webpack_i__]; |
package/package/dist/sockets/WHMEventSource.js |
5 | NO_HASOWN | for(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, { |
package/package/dist/sockets/WHMEventSource.js |
47 | NO_HASOWN | for(var __webpack_i__ in __webpack_exports__)if (-1 === [ |
package/package/dist/sockets/WHMEventSource.js |
49 | DYNAMIC_PROP_WRITE | ].indexOf(__webpack_i__)) exports[__webpack_i__] = __webpack_exports__[__webpack_i__]; |
package/package/dist/sockets/WDSSocket.js |
14 | NO_HASOWN | for(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, { |
package/package/dist/sockets/WDSSocket.js |
58 | NO_HASOWN | for(var __webpack_i__ in __webpack_exports__)if (-1 === [ |
package/package/dist/sockets/WDSSocket.js |
60 | DYNAMIC_PROP_WRITE | ].indexOf(__webpack_i__)) exports[__webpack_i__] = __webpack_exports__[__webpack_i__]; |
package/package/dist/sockets/utils/getSocketUrlParts.js |
14 | NO_HASOWN | for(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, { |
package/package/dist/sockets/utils/getSocketUrlParts.js |
46 | DYNAMIC_PROP_WRITE | parsedQuery[key] = value; |
package/package/dist/sockets/utils/getSocketUrlParts.js |
81 | DYNAMIC_PROP_WRITE | exports["default"] = __webpack_exports__["default"]; |
package/package/dist/sockets/utils/getSocketUrlParts.js |
82 | NO_HASOWN | for(var __webpack_i__ in __webpack_exports__)if (-1 === [ |
package/package/dist/sockets/utils/getSocketUrlParts.js |
84 | DYNAMIC_PROP_WRITE | ].indexOf(__webpack_i__)) exports[__webpack_i__] = __webpack_exports__[__webpack_i__]; |
package/package/dist/sockets/utils/getCurrentScriptSource.js |
5 | NO_HASOWN | for(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, { |
package/package/dist/sockets/utils/getCurrentScriptSource.js |
39 | DYNAMIC_PROP_WRITE | exports["default"] = __webpack_exports__["default"]; |
package/package/dist/sockets/utils/getCurrentScriptSource.js |
40 | NO_HASOWN | for(var __webpack_i__ in __webpack_exports__)if (-1 === [ |
package/package/dist/sockets/utils/getCurrentScriptSource.js |
42 | DYNAMIC_PROP_WRITE | ].indexOf(__webpack_i__)) exports[__webpack_i__] = __webpack_exports__[__webpack_i__]; |
package/package/dist/sockets/utils/getUrlFromParts.js |
5 | NO_HASOWN | for(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, { |
| ... | ... | ... | (47 more sinks) |
Remediation
- Validate all configuration options and callbacks before use
- Avoid passing untrusted functions or objects as configuration
- Use TypeScript strict typing to prevent unexpected function injection
- Review all entry points that accept user-controlled configuration objects
- 主要语言
- TypeScript
- 星标
- 20
- 派生
- 13
- 平均合并
- 2 小时 55 分钟
- 30 天内合并 PR
- 6
环境准备
这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
rstackjs/rspack-plugin-react-refresh 的其他 Issue
-
难度 4/5 3-5 天 新手友好度 38/100
-
难度 3/5 1-2 天 新手友好度 52/100
-
难度 3/5 1-2 天 新手友好度 35/100
查看 rstackjs/rspack-plugin-react-refresh 的全部 Issue
相似的 Issue
-
难度 2/5 1-3 小时 新手友好度 88/100
openedx/frontend-app-authoring#3274 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 88/100
-
area/documentation status/need-triage
难度 1/5 1 小时以内 新手友好度 95/100
google-gemini/gemini-cli#29548 ·
维护者通常 1 天内回复
-
sdk-typescript vector-store
难度 2/5 半天 新手友好度 82/100
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 82/100
维护者通常 1 天内回复