PT-2026-98195 · Npm · @Rsdoctor/Rspack-Plugin

CVE-2026-61782

·

Published

2026-09-24

·

Updated

2026-09-29

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions @rsdoctor/rspack-plugin versions prior to 1.5.16
Description The default report HTTP server started by @rsdoctor/rspack-plugin binds to all network interfaces (0.0.0.0) and serves a POST /api/data/key endpoint without authentication and with wildcard CORS (Access-Control-Allow-Origin: *). This allows a network-adjacent or remote attacker to send an unauthenticated request to retrieve sensitive build metadata, including the full source code of all compiled JavaScript modules via the moduleCodeMap variable, serialized build configurations via the configs variable, and error details. The server is enabled by default in non-CI environments.
Recommendations Update @rsdoctor/rspack-plugin to version 1.5.16 or later. As a temporary workaround, disable the report server by setting disableClientServer: true in the plugin configuration. Restrict external access to the report server port using firewall rules. Avoid using server.cors: true or server.cors.origin: '*' in the configuration.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61782
GHSA-JMG2-RCXH-W8Q3

Affected Products

@Rsdoctor/Rspack-Plugin