Skip to content

fix(deps): patch webpack-dev-middleware path traversal - #4356

Merged
martinothamar merged 1 commit into
Altinn:mainfrom
martinothamar-agent:security/webpack-dev-middleware-triage
Oct 3, 2026
Merged

martinothamar merged 1 commit into
Altinn:mainfrom
martinothamar-agent:security/webpack-dev-middleware-triage

Conversation

@martinothamar-agent

@martinothamar-agent martinothamar-agent commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Description

Update the frontend development server's middleware to fix CVE-2026-76844, which can expose files outside the build output directory when a slashless public path is configured.

Refresh yarn.lock so webpack-dev-server@5.2.6 resolves webpack-dev-middleware@7.4.6 instead of 7.4.2, within its existing ^7.4.2 range. Include the updated middleware's required memfs, MIME, and transitive dependencies. No manifest or application configuration changes are needed.

The checked-in configuration does not set a slashless middleware public path: its effective default is /. The /schemas path belongs to devServer.static, a separate handler. Patch anyway because an upstream fix is available. Production releases contain static build artifacts.

Although the advisory prose says there is no 7.x backport, the 7.4.6 release, containment check in its source, and GitHub advisory metadata confirm the fix in 7.4.6.

Related Issue(s)

Verification/QA

Verified locally with Node 22 and the repository's Yarn 4.14.1 after rebasing onto main at 36726c20b380cbe90dc22a5c2bc486d24b055da0. Regenerated the middleware update from the current main lockfile to resolve the MIME descriptor conflict and verified that the axios, DOMPurify, fast-uri, and brace-expansion fixes remain intact:

  • CYPRESS_INSTALL_BINARY=0 yarn install --immutable — passed; Cypress binary download skipped because browser E2E tests were not run.
  • yarn why webpack-dev-middleware — only 7.4.6 is resolved.
  • yarn build — production build passed.
  • NODE_ENV=development yarn webpack --config webpack.config.development.js --mode development — development build passed.
  • yarn lint and yarn tsc — passed.
  • yarn test --maxWorkers=2 — 165 suites and 3,606 tests passed; 1 suite and 61 tests skipped; both snapshots passed.
  • HTTP smoke test using installed webpack-dev-server@5.2.6, webpack, and middleware 7.4.6, with publicPath: '/assets': normal JavaScript returned HTTP 200 with a JavaScript content type; /assets../secret and /assets%2e%2e/secret returned HTTP 403. The secret fixture was placed outside the output directory in the middleware's actual in-memory filesystem.
  • Compared the published 7.4.2 and 7.4.6 path resolvers: 7.4.2 resolves the traversal outside the output root; 7.4.6 rejects it before filesystem access. Default-path and normal-asset checks passed.
  • git diff --check — passed. Yarn generated and validated the lockfile; Prettier does not provide a parser for it.

The full Jest run passed as detailed above. Cypress browser E2E tests were not run. No application source, UI, or terminal workflow changes.

  • Manual functionality testing
    • I have tested these changes manually
    • Creator of the original issue (or service owner) has been contacted for manual testing (or will be contacted when released in alpha)
    • No testing done/necessary
  • Automated tests
    • Unit test(s) have been added/updated
    • Cypress E2E test(s) have been added/updated
    • No automatic tests are needed here (no functional changes/additions)
    • I want someone to help me make some tests
  • UU/WCAG
    • I have tested with a screen reader/keyboard navigation/automated wcag validator
    • No testing done/necessary (no DOM/visual changes)
    • I want someone to help me perform accessibility testing
  • User documentation @ altinn-studio-docs
    • Has been added/updated
    • No functionality has been changed/added, so no documentation is needed
    • I will do that later/have created an issue
  • Support in Altinn Studio
    • Issue(s) created for support in Studio
    • This change/feature does not require any changes to Altinn Studio
  • Sprint board
    • The original issue (or this PR itself) has been added to the Team Apps project and to the current sprint board
    • I don't have permissions to do that, please help me out
  • Labels
    • I have added a kind/* and backport* label to this PR for proper release notes grouping
    • I don't have permissions to add labels, please help me out

Suggested labels: kind/dependencies, backport-ignore (development dependency only).

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Review was skipped due to path filters

⛔ Files ignored due to path filters (1)
  • yarn.lock is excluded by !**/yarn.lock, !**/*.lock

CodeRabbit blocks several paths by default. You can override this behavior by explicitly including those paths in the path filters. For example, including **/dist/** will override the default block on the dist directory, by removing the pattern from both the lists.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 841432bc-0443-44af-a14f-2a1711be3e7c

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@martinothamar martinothamar added kind/dependencies Pull requests that update a dependency file dependencies Pull requests that update a dependency file backport-ignore This PR is a new feature and should not be cherry-picked onto release branches labels Oct 1, 2026
@martinothamar-agent
martinothamar-agent force-pushed the security/webpack-dev-middleware-triage branch from 76f8eee to cc72e45 Compare October 2, 2026 08:35
@martinothamar
martinothamar merged commit 4d7c8d3 into Altinn:main Oct 3, 2026
10 of 11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport-ignore This PR is a new feature and should not be cherry-picked onto release branches dependencies Pull requests that update a dependency file kind/dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants