adobe / adobe/reactor-sandbox

Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code

Open
#95 4 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
9
Forks
11
PR merge metrics
No merged PRs in 30d

Description

### Expected Behaviour

@babel/traverse v7.23.2 or higher is used.

### Actual Behaviour

@babel/traverse v7.15.4 is used in package.json. https://github.com/adobe/reactor-sandbox/blob/4d7e0c088316821484c42f6f13ebdca33ed72af0/package.json#L55

### More information

I received this Github dependabot alert in my repository for my Launch extension:

#### Impact
Using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when using plugins that rely on the `path.evaluate()` or `path.evaluateTruthy()` internal Babel methods.

Known affected plugins are:

- `@babel/plugin-transform-runtime`
- `@babel/preset-env` when using its [useBuiltIns](https://babeljs.io/docs/babel-preset-env#usebuiltins) option
- Any "polyfill provider" plugin that depends on `@babel/helper-define-polyfill-provider`, such as `babel-plugin-polyfill-corejs3`, `babel-plugin-polyfill-corejs2`, `babel-plugin-polyfill-es-shims`, `babel-plugin-polyfill-regenerator`
- No other plugins under the `@babel/` namespace are impacted, but third-party plugins might be.

**Users that only compile trusted code are not impacted.**

#### Patches
The vulnerability has been fixed in `@babel/traverse@7.23.2`.

Babel 6 does not receive security fixes anymore (see [Babel's security policy](https://github.com/babel/babel/security/policy)), hence there is no patch planned for `babel-traverse@6`.

#### Workarounds
- Upgrade `@babel/traverse` to v7.23.2 or higher. You can do this by deleting it from your package manager's lockfile and re-installing the dependencies. `@babel/core` >=7.23.2 will automatically pull in a non-vulnerable version.
- If you cannot upgrade `@babel/traverse` and are using one of the affected packages mentioned above, upgrade them to their latest version to avoid triggering the vulnerable code path in affected `@babel/traverse` versions:
- `@babel/plugin-transform-runtime` v7.23.2
- `@babel/preset-env` v7.23.2
- `@babel/helper-define-polyfill-provider` v0.4.3
- `babel-plugin-polyfill-corejs2` v0.4.6
- `babel-plugin-polyfill-corejs3` v0.8.5
- `babel-plugin-polyfill-es-shims` v0.10.0
- `babel-plugin-polyfill-regenerator` v0.5.3

Contributor guide

Open the contributing guide

Research direction

Inspect package.json at the referenced line, where @babel/traverse is pinned to 7.15.4. Update the dependency to 7.23.2 or higher, then verify that the resolved dependency no longer uses the vulnerable version; the issue does not mention a specific test file.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
1/5
Estimated time
Under an hour
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.