fix(deps): patch webpack-dev-middleware path traversal - #4356
martinothamar merged 1 commit into
Conversation
|
Important Review skippedReview was skipped due to path filters ⛔ Files ignored due to path filters (1)
CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
76f8eee to
cc72e45
Compare
Description
Update the frontend development server's middleware to fix CVE-2026-76844, which can expose files outside the build output directory when a slashless public path is configured.
Refresh
yarn.locksowebpack-dev-server@5.2.6resolveswebpack-dev-middleware@7.4.6instead of7.4.2, within its existing^7.4.2range. Include the updated middleware's requiredmemfs, MIME, and transitive dependencies. No manifest or application configuration changes are needed.The checked-in configuration does not set a slashless middleware public path: its effective default is
/. The/schemaspath belongs todevServer.static, a separate handler. Patch anyway because an upstream fix is available. Production releases contain static build artifacts.Although the advisory prose says there is no 7.x backport, the 7.4.6 release, containment check in its source, and GitHub advisory metadata confirm the fix in 7.4.6.
Related Issue(s)
Verification/QA
Verified locally with Node 22 and the repository's Yarn 4.14.1 after rebasing onto
mainat36726c20b380cbe90dc22a5c2bc486d24b055da0. Regenerated the middleware update from the current main lockfile to resolve the MIME descriptor conflict and verified that the axios, DOMPurify, fast-uri, and brace-expansion fixes remain intact:CYPRESS_INSTALL_BINARY=0 yarn install --immutable— passed; Cypress binary download skipped because browser E2E tests were not run.yarn why webpack-dev-middleware— only 7.4.6 is resolved.yarn build— production build passed.NODE_ENV=development yarn webpack --config webpack.config.development.js --mode development— development build passed.yarn lintandyarn tsc— passed.yarn test --maxWorkers=2— 165 suites and 3,606 tests passed; 1 suite and 61 tests skipped; both snapshots passed.webpack-dev-server@5.2.6, webpack, and middleware 7.4.6, withpublicPath: '/assets': normal JavaScript returned HTTP 200 with a JavaScript content type;/assets../secretand/assets%2e%2e/secretreturned HTTP 403. The secret fixture was placed outside the output directory in the middleware's actual in-memory filesystem.git diff --check— passed. Yarn generated and validated the lockfile; Prettier does not provide a parser for it.The full Jest run passed as detailed above. Cypress browser E2E tests were not run. No application source, UI, or terminal workflow changes.
kind/*andbackport*label to this PR for proper release notes groupingSuggested labels:
kind/dependencies,backport-ignore(development dependency only).