Executive brief
webcrack is a JavaScript decompiler/unpacker tool used by developers to analyze bundled code. The vulnerability allows an attacker to write arbitrary files to a Windows system when a user unpacks a malicious bundle, potentially enabling code execution by hijacking legitimate Node.js modules. This affects any developer using webcrack on Windows to analyze untrusted code.
Technical details
The vulnerability is a path traversal flaw in bundle.ts that incorrectly validates file paths during unpacking. The code uses Node.js POSIX path utilities (normalize, join) which do not recognize backslashes as path separators, causing the path traversal check to fail on Windows. An attacker crafts a malicious bundle with module names containing backslash sequences (e.g., `./\\..\node_modules\debug\src\index`) that bypass validation and write files to arbitrary locations. The attack requires user interaction (calling the save method on a malicious bundle) but no privileges. Successful exploitation leads to arbitrary JavaScript file writes, enabling module hijacking and code execution. The fix was released in version 2.14.1.
Affected products
- webcrack webcrack <= 2.14.0
Timeline
- 2024-08-14: disclosed
- 2024-08-14: patched: Fixed in version 2.14.1