CyberRota Analysis
AI-GeneratedThe Rsdoctor build analyzer for Rspack versions prior to 1.5.16 is vulnerable due to its default HTTP server configuration, which binds to all network interfaces and exposes an unauthenticated endpoint that allows remote attackers to access sensitive build metadata and source code. This high-severity vulnerability poses a significant risk to developers using Rsdoctor in non-CI environments, as it requires no special configuration to exploit. Organizations utilizing this tool should prioritize upgrading to version 1.5.16 to mitigate potential data exposure.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Rsdoctor is a build analyzer tailored for projects built with Rspack. Prior to version 1.5.16, the default Rsdoctor report HTTP server started by `@rsdoctor/rspack-plugin` binds to all network interfaces (`0.0.0.0`) and serves a `POST /api/data/key` endpoint with no authentication and wildcard CORS (`Access-Control-Allow-Origin: *`). Any network-adjacent or remote attacker can send a single unauthenticated request to retrieve the full source code of all compiled JavaScript modules (`moduleCodeMap`), serialized build configuration (`configs`), error details, and other sensitive build metadata. This server is enabled by default in non-CI environments, requiring no special configuration from the victim developer. Version 1.5.16 patches the issue.