OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-61782

HIGH · CVSS 7.5 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The Rsdoctor build analyzer for Rspack versions prior to 1.5.16 is vulnerable due to its default HTTP server configuration, which binds to all network interfaces and exposes an unauthenticated endpoint that allows remote attackers to access sensitive build metadata and source code. This high-severity vulnerability poses a significant risk to developers using Rsdoctor in non-CI environments, as it requires no special configuration to exploit. Organizations utilizing this tool should prioritize upgrading to version 1.5.16 to mitigate potential data exposure.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-61782
Severity
HIGH
CVSS
7.5
EPSS
0.36%
Java

Original NVD Description

Rsdoctor is a build analyzer tailored for projects built with Rspack. Prior to version 1.5.16, the default Rsdoctor report HTTP server started by `@rsdoctor/rspack-plugin` binds to all network interfaces (`0.0.0.0`) and serves a `POST /api/data/key` endpoint with no authentication and wildcard CORS (`Access-Control-Allow-Origin: *`). Any network-adjacent or remote attacker can send a single unauthenticated request to retrieve the full source code of all compiled JavaScript modules (`moduleCodeMap`), serialized build configuration (`configs`), error details, and other sensitive build metadata. This server is enabled by default in non-CI environments, requiring no special configuration from the victim developer. Version 1.5.16 patches the issue.