Executive brief
React Developer Tools is a browser extension used by developers to debug and profile React applications. The extension contains a vulnerability where it listens to messages from any webpage and performs unsanitized HTTP requests based on untrusted input, allowing a malicious website to exploit the victim's browser to fetch arbitrary URLs. This could lead to server-side request forgery (SSRF) attacks or retrieval of sensitive internal resources.
Technical details
The React Developer Tools extension registers a message listener using window.addEventListener('message', ...) in a content script that is accessible to any active webpage. The listener processes 'fetch-file-with-cache' events and derives URLs from the received message, passing them to fetch() without validation or sanitization. This allows any malicious webpage to invoke arbitrary HTTP requests through the victim's browser context. The vulnerability affects react-devtools-core versions prior to 4.28.4. The fix refactored the messaging logic to use chrome.runtime.sendMessage API instead of window messaging, ensuring only privileged extension code can trigger fetches (CWE-116, CWE-285).
Affected products
- Meta React Developer Tools before 4.28.4
Timeline
- 2023-10-19: disclosed
- 2023-09-25: patched: Fix merged in PR #27417