PT-2026-98195 · Npm · @Rsdoctor/Rspack-Plugin
CVE-2026-61782
·
Published
2026-09-24
·
Updated
2026-09-29
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
@rsdoctor/rspack-plugin versions prior to 1.5.16
Description
The default report HTTP server started by
@rsdoctor/rspack-plugin binds to all network interfaces (0.0.0.0) and serves a POST /api/data/key endpoint without authentication and with wildcard CORS (Access-Control-Allow-Origin: *). This allows a network-adjacent or remote attacker to send an unauthenticated request to retrieve sensitive build metadata, including the full source code of all compiled JavaScript modules via the moduleCodeMap variable, serialized build configurations via the configs variable, and error details. The server is enabled by default in non-CI environments.Recommendations
Update @rsdoctor/rspack-plugin to version 1.5.16 or later.
As a temporary workaround, disable the report server by setting
disableClientServer: true in the plugin configuration.
Restrict external access to the report server port using firewall rules.
Avoid using server.cors: true or server.cors.origin: '*' in the configuration.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Rsdoctor/Rspack-Plugin