chore(deps): update dependency @rsdoctor/rspack-plugin to v1.5.16 [security] - #507
Merged
renovate[bot] merged 1 commit intoOct 3, 2026
Merged
Conversation
renovate
Bot
deleted the
renovate/npm-rsdoctor-rspack-plugin-vulnerability
branch
October 3, 2026 23:07
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.5.12→1.5.16@rsdoctor/rspack-plugin has Unauthenticated HTTP API that Exposes Project Source Code and Build Metadata
CVE-2026-61782 / GHSA-jmg2-rcxh-w8q3
More information
Details
Summary
The default Rsdoctor report HTTP server started by
@rsdoctor/rspack-pluginbinds to all network interfaces (0.0.0.0) and serves aPOST /api/data/keyendpoint with no authentication and wildcard CORS (Access-Control-Allow-Origin: *). Any network-adjacent or remote attacker can send a single unauthenticated request to retrieve the full source code of all compiled JavaScript modules (moduleCodeMap), serialized build configuration (configs), error details, and other sensitive build metadata. This server is enabled by default in non-CI environments, requiring no special configuration from the victim developer.Details
Root cause: server binds to all interfaces with no authentication and no key allowlist.
The vulnerability is composed of four independently observable defects that together create a complete unauthenticated information-disclosure path:
1. Server binds to
0.0.0.0(all interfaces)packages/utils/src/build/server.ts:107callsserver.listen(port, callback)without ahostargument. Node.js defaults to0.0.0.0, exposing the server on every network interface of the developer's machine, including LAN interfaces.2. Wildcard CORS enabled unconditionally
packages/sdk/src/sdk/server/index.ts:106appliescors()middleware with no origin restriction, and:203–204additionally setsAccess-Control-Allow-Origin: *explicitly on every API response, allowing cross-origin browser requests from any domain.3.
POST /api/data/keyregistered with no authentication middlewarepackages/sdk/src/sdk/server/apis/data.ts:6registers the route via@Router.post. There is no authentication guard, token check, or session validation anywhere in the middleware chain.4.
keyis passed togetStoreData()without an allowlistpackages/sdk/src/sdk/server/apis/base.ts:29–39indexes the entire SDK data store directly using the attacker-controlledkey, including dot-path traversal for nested keys.Source-to-sink data flow:
packages/rspack-plugin/src/plugin.ts:111packages/core/src/inner-plugins/utils/config.ts:98,110–115disableClientServerdefaults tofalse; server starts in all non-CI buildspackages/utils/src/build/server.ts:83,1070.0.0.0packages/sdk/src/sdk/server/index.ts:106,203packages/sdk/src/sdk/server/apis/data.ts:6,13,29keyaccepted from request bodypackages/sdk/src/sdk/server/apis/base.ts:29,36,39keyindexessdk.getStoreData()with no allowlistpackages/sdk/src/sdk/sdk/index.ts:487,491moduleCodeMapgetter calls_moduleGraph.toCodeData()packages/graph/src/graph/module-graph/graph.ts:464–469toCodeData()returns all module source objectspackages/graph/src/graph/module-graph/module.ts:248–250source,transformed, andparsedSourcepackages/sdk/src/sdk/server/router.ts:119,125Default configuration ensures source code is captured:
packages/core/src/inner-plugins/utils/config.tsshows thatnoModuleSource,noAssetsAndModuleSource, andnoCodeall default tofalse, causingnormalizeReportTypeto returnSDK.ToDataType.Normal. This means module source code is stored in the SDK data store by default and retrievable via themoduleCodeMapkey.PoC
Original PoC
Environment setup:
Exploit (from any host on the same LAN, no authentication):
Expected response (excerpt):
{ "...": "...", "source": "const INTERNAL_API_KEY = 'rsdoctor-secret-marker-123';\nconsole.log(INTERNAL_API_KEY);\n", "...": "..." }Secondary probe: exfiltrate build configuration and local paths:
Automated PoC (Docker-based, self-contained reproduction):
The Docker-based reproduction builds and starts the vulnerable project inside a container, then executes
poc.pyto confirm source code exfiltration. The PoC embeds the marker stringrsdoctor-vuln-001-secret-EXFIL-abc123in the compiled source and asserts its presence in the unauthenticated API response:Recommended patch:
Minimal browser-based PoC
A malicious website can also attempt to read data from a local Rsdoctor report server by sending a browser request to
127.0.0.1orlocalhost.If the report server is reachable over the local network, an attacker may also target the victim machine's LAN address:
In affected versions, the response may contain sensitive build metadata or compiled module source code.
Impact
This is an unauthenticated remote information disclosure vulnerability. Any attacker who can reach the developer's machine over the network (LAN, VPN, shared Wi-Fi, corporate network) can retrieve:
moduleCodeMap)configs)errors)envinfo)The server is started automatically whenever a developer runs a build with the Rsdoctor plugin outside of a CI environment (
disableClientServerdefaults tofalse). No user interaction or special configuration is required from the victim. A single unauthenticated HTTP POST request is sufficient to exfiltrate all module source code.Impacted parties include individual developers and organizations whose developers run Rsdoctor on machines connected to any shared or semi-trusted network, and any CI system that runs Rsdoctor in a non-CI-detected environment.
Patched Behavior
The patched version changes the report server's default security model:
127.0.0.1by default.localhost,*.localhost,127.0.0.1, and[::1].Upgrade Path
Upgrade Rsdoctor packages to the patched version:
Most users do not need additional configuration after upgrading.
CORS Configuration Behavior
The patched version aligns Rsdoctor's CORS behavior with a safer default model. In particular, partial CORS options no longer drop the default local-origin protection.
server.corsundefinedfalsetruecors({}); effectively allows arbitrary origins and is not recommended{ credentials: true }credentials: true{ origin: 'https://example.com' }{ origin: '*' }{ origin: false }Access-Control-Allow-Origin{ origin: fn }{ origin: /regex/ }Recommended configuration
For most users, leave
server.corsunset:If another local development frontend needs to access the report server, configure an exact origin:
Avoid permissive CORS configuration:
These configurations explicitly opt out of the safer default CORS behavior.
Breaking Changes
The patched version intentionally tightens the report server's access model.
1. The report server is local-only by default
The report server is no longer intended to be accessed from arbitrary LAN hosts or remote machines by default.
If your workflow depended on opening the Rsdoctor report server from another device on the network, that workflow may stop working after upgrading. The recommended approach is to access the report from the same machine that started the build, or to use generated static report output instead of exposing the development report server.
2. Cross-origin access is restricted by default
Web pages from non-local origins can no longer read report server responses by default.
If you have a trusted local integration, configure the exact allowed origin through
server.cors.origin.3. Custom WebSocket clients must use the tokenized socket URL
The report WebSocket now requires a per-server token.
Custom clients must not construct the socket URL manually, for example:
Instead, they must use the tokenized socket URL provided by the report runtime data.
4.
server.cors: trueremains an explicit opt-outserver.cors: trueuses the default behavior of thecorsmiddleware and is effectively permissive. This behavior is kept for compatibility, but it is not recommended for untrusted environments.Workarounds
If upgrading immediately is not possible, users can reduce exposure by disabling the report server:
Additional mitigations:
server.cors: true.server.cors.origin: '*'.These workarounds do not fully address every attack path. Upgrading to a patched version is recommended.
Reproduction artifacts
Dockerfilepoc.pySeverity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
web-infra-dev/rsdoctor (@rsdoctor/rspack-plugin)
v1.5.16Compare Source
What's Changed
New Features 🎉
Bug Fixes 🐞
Other Changes
Full Changelog: web-infra-dev/rsdoctor@v1.5.15...v1.5.16
v1.5.15Compare Source
What's Changed
Bug Fixes 🐞
Full Changelog: web-infra-dev/rsdoctor@v1.5.14...v1.5.15
v1.5.14Compare Source
What's Changed
Full Changelog: web-infra-dev/rsdoctor@v1.5.13...v1.5.14
v1.5.13Compare Source
What's Changed
Performance 🚀
Bug Fixes 🐞
Other Changes
Full Changelog: web-infra-dev/rsdoctor@v1.5.12...v1.5.13
Configuration
📅 Schedule: (in timezone Asia/Shanghai)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.