CVE-2026-61782
Description
Rsdoctor is a build analyzer tailored for projects built with Rspack. Prior to version 1.5.16, the default Rsdoctor report HTTP server started by @rsdoctor/rspack-plugin binds to all network interfaces (0.0.0.0) and serves a POST /api/data/key endpoint with no authentication and wildcard CORS (Access-Control-Allow-Origin: *). Any network-adjacent or remote attacker can send a single unauthenticated request to retrieve the full source code of all compiled JavaScript modules (moduleCodeMap), serialized build configuration (configs), error details, and other sensitive build metadata. This server is enabled by default in non-CI environments, requiring no special configuration from the victim developer. Version 1.5.16 patches the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.5.16
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-jmg2-rcxh-w8q3ghsaADVISORY
- github.com/web-infra-dev/rsdoctor/commit/602eb306a49b6d19c4c1ea9d8ee0f8caab9e208fghsa
- github.com/web-infra-dev/rsdoctor/commit/e9aaef21f85becfe43a46f716509f41ea5edeb40ghsa
- github.com/web-infra-dev/rsdoctor/pull/1744ghsa
- github.com/web-infra-dev/rsdoctor/pull/1758ghsa
- github.com/web-infra-dev/rsdoctor/security/advisories/GHSA-jmg2-rcxh-w8q3nvd
- nvd.nist.gov/vuln/detail/CVE-2026-61782ghsa
News mentions
0No linked articles in our index yet.