package/package/dist/index.js |
14 |
NO_HASOWN |
for(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, { |
package/package/dist/index.js |
248 |
DYNAMIC_PROP_WRITE |
exports["default"] = __webpack_exports__["default"]; |
package/package/dist/index.js |
249 |
NO_HASOWN |
for(var __webpack_i__ in __webpack_exports__)if (-1 === [ |
package/package/dist/index.js |
252 |
DYNAMIC_PROP_WRITE |
].indexOf(__webpack_i__)) exports[__webpack_i__] = __webpack_exports__[__webpack_i__]; |
package/package/dist/sockets/WHMEventSource.js |
5 |
NO_HASOWN |
for(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, { |
package/package/dist/sockets/WHMEventSource.js |
47 |
NO_HASOWN |
for(var __webpack_i__ in __webpack_exports__)if (-1 === [ |
package/package/dist/sockets/WHMEventSource.js |
49 |
DYNAMIC_PROP_WRITE |
].indexOf(__webpack_i__)) exports[__webpack_i__] = __webpack_exports__[__webpack_i__]; |
package/package/dist/sockets/WDSSocket.js |
14 |
NO_HASOWN |
for(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, { |
package/package/dist/sockets/WDSSocket.js |
58 |
NO_HASOWN |
for(var __webpack_i__ in __webpack_exports__)if (-1 === [ |
package/package/dist/sockets/WDSSocket.js |
60 |
DYNAMIC_PROP_WRITE |
].indexOf(__webpack_i__)) exports[__webpack_i__] = __webpack_exports__[__webpack_i__]; |
package/package/dist/sockets/utils/getSocketUrlParts.js |
14 |
NO_HASOWN |
for(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, { |
package/package/dist/sockets/utils/getSocketUrlParts.js |
46 |
DYNAMIC_PROP_WRITE |
parsedQuery[key] = value; |
package/package/dist/sockets/utils/getSocketUrlParts.js |
81 |
DYNAMIC_PROP_WRITE |
exports["default"] = __webpack_exports__["default"]; |
package/package/dist/sockets/utils/getSocketUrlParts.js |
82 |
NO_HASOWN |
for(var __webpack_i__ in __webpack_exports__)if (-1 === [ |
package/package/dist/sockets/utils/getSocketUrlParts.js |
84 |
DYNAMIC_PROP_WRITE |
].indexOf(__webpack_i__)) exports[__webpack_i__] = __webpack_exports__[__webpack_i__]; |
package/package/dist/sockets/utils/getCurrentScriptSource.js |
5 |
NO_HASOWN |
for(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, { |
package/package/dist/sockets/utils/getCurrentScriptSource.js |
39 |
DYNAMIC_PROP_WRITE |
exports["default"] = __webpack_exports__["default"]; |
package/package/dist/sockets/utils/getCurrentScriptSource.js |
40 |
NO_HASOWN |
for(var __webpack_i__ in __webpack_exports__)if (-1 === [ |
package/package/dist/sockets/utils/getCurrentScriptSource.js |
42 |
DYNAMIC_PROP_WRITE |
].indexOf(__webpack_i__)) exports[__webpack_i__] = __webpack_exports__[__webpack_i__]; |
package/package/dist/sockets/utils/getUrlFromParts.js |
5 |
NO_HASOWN |
for(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, { |
| ... |
... |
... |
(47 more sinks) |
hi, we are a security team. We found a vulnerability in your project.
Vulnerability Report: @rspack/plugin-react-refresh
Package Information
Vulnerability Details
EX0001: Code Execution
Verified Output:
[CASE_ID=EX0001] [VULN_CMD] overlay.entry taint triggered error with markerTaint Analysis:
Sink Location:
package/package/dist/sockets/WDSSocket.jsline 51PoC Code:
PoC File: poc_EX0001.js
EX0004: Code Execution
Verified Output:
[CASE_ID=EX0004] [VULN_CMD] overlay.entry query taint triggered error with markerTaint Analysis:
Sink Location:
package/package/dist/sockets/WDSSocket.jsline 51PoC Code:
PoC File: poc_EX0004.js
Affected Sinks
package/package/dist/index.jsfor(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, {package/package/dist/index.jsexports["default"] = __webpack_exports__["default"];package/package/dist/index.jsfor(var __webpack_i__ in __webpack_exports__)if (-1 === [package/package/dist/index.js].indexOf(__webpack_i__)) exports[__webpack_i__] = __webpack_exports__[__webpack_i__];package/package/dist/sockets/WHMEventSource.jsfor(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, {package/package/dist/sockets/WHMEventSource.jsfor(var __webpack_i__ in __webpack_exports__)if (-1 === [package/package/dist/sockets/WHMEventSource.js].indexOf(__webpack_i__)) exports[__webpack_i__] = __webpack_exports__[__webpack_i__];package/package/dist/sockets/WDSSocket.jsfor(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, {package/package/dist/sockets/WDSSocket.jsfor(var __webpack_i__ in __webpack_exports__)if (-1 === [package/package/dist/sockets/WDSSocket.js].indexOf(__webpack_i__)) exports[__webpack_i__] = __webpack_exports__[__webpack_i__];package/package/dist/sockets/utils/getSocketUrlParts.jsfor(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, {package/package/dist/sockets/utils/getSocketUrlParts.jsparsedQuery[key] = value;package/package/dist/sockets/utils/getSocketUrlParts.jsexports["default"] = __webpack_exports__["default"];package/package/dist/sockets/utils/getSocketUrlParts.jsfor(var __webpack_i__ in __webpack_exports__)if (-1 === [package/package/dist/sockets/utils/getSocketUrlParts.js].indexOf(__webpack_i__)) exports[__webpack_i__] = __webpack_exports__[__webpack_i__];package/package/dist/sockets/utils/getCurrentScriptSource.jsfor(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, {package/package/dist/sockets/utils/getCurrentScriptSource.jsexports["default"] = __webpack_exports__["default"];package/package/dist/sockets/utils/getCurrentScriptSource.jsfor(var __webpack_i__ in __webpack_exports__)if (-1 === [package/package/dist/sockets/utils/getCurrentScriptSource.js].indexOf(__webpack_i__)) exports[__webpack_i__] = __webpack_exports__[__webpack_i__];package/package/dist/sockets/utils/getUrlFromParts.jsfor(var key in definition)if (__webpack_require__.o(definition, key) && !__webpack_require__.o(exports1, key)) Object.defineProperty(exports1, key, {Remediation