Executive brief
Stencil core is a compiler and toolchain for building web components. Its development server exposes a WebSocket interface that returns build metadata without authentication, allowing unauthenticated attackers on the same network to read sensitive project paths, source directories, output lists, and component structure. This information leak could aid further attacks by revealing system architecture and file organization.
Technical details
The vulnerability is an information disclosure (CWE-200) in the WebSocket debugging channel of Stencil's dev server. The channel accepts unauthenticated WebSocket connections without origin checks and returns build results with insufficient field trimming, exposing the project root, source directory, output file list, component graph, and error context with absolute file paths. Exploitation requires only network access to the dev server port and a completed build; no authentication, credentials, or user interaction is needed.
Affected products
- Stencil core 4.43.5 confirmed affected; same code path present in 4.45.0 and development branch
Timeline
- 2026-09-21: disclosed: CVE-2026-79319 published
- 2026-08-04: other: Vulnerability reported