Junglewise Threat Intelligence

Rspack DOM Clobbering in AutoPublicPathRuntimeModule

Severity: low · CVSS 3.1 · Published 2024-09-19

Vendors: npm.

Executive brief

Rspack's automatic public path resolution module contains a vulnerability that allows attackers to inject malicious HTML elements (like img tags) into web pages, which can trick the build tool into loading JavaScript from attacker-controlled servers instead of the legitimate application server. In practice, this could lead to arbitrary code execution and account compromise on any website using vulnerable Rspack-compiled bundles, particularly when combined with features that allow user-controlled HTML input like comments, forums, or email clients.

Technical details

A DOM Clobbering vulnerability exists in Rspack's AutoPublicPathRuntimeModule when the output.publicPath configuration is unset or set to "auto". The runtime code attempts to resolve the script's public path by reading document.currentScript.src, but this property can be shadowed by attacker-controlled HTML elements (e.g., an img tag with name="currentScript"). When shadowed, the lookup returns the malicious element's src attribute instead, causing the webpack_require.p base URL to point to an attacker's domain. Subsequent dynamic script loads via webpack will then fetch from the attacker's server rather than the legitimate application server, enabling arbitrary JavaScript execution with the victim's privileges. The vulnerability requires the attacker to inject scriptless HTML into the page (via markdown, forums, email clients, or HTML injection vulnerabilities) and is patched in Rspack 1.0.0-rc.1 and later.

Affected products

  • web-infra-dev @rspack/core <1.0.0-rc.1

Timeline

  • 2024-09-19: disclosed: Vulnerability disclosed on GitHub Security Advisory
  • 2024-09-19: patched: Patched in version 1.0.0-rc.1

References