bcgov / bcgov/bcgov-wordpress-block-theme

Security Vulnerabilities in @wordpress/scripts Dependencies: webpack-dev-server

Open
#198 0 comments 0 reactions 1 assignee Claimed by @ShawnTurple View on GitHub
Dominant language
PHP
Stars
5
Forks
5
PR merge metrics
No merged PRs in 30d

Description

# Security Vulnerabilities in @wordpress/scripts Dependencies: webpack-dev-server

**Description:**
Two moderate severity security vulnerabilities have been identified in the webpack-dev-server dependency (versions <=5.2.0) which is a dependency of @wordpress/scripts package used in our theme.

**Current Versions:**
- @wordpress/scripts: 30.20.0
- webpack-dev-server: ^5.2.2 (direct dependency)

**Vulnerabilities:**
1. **GHSA-9jgg-88mc-972h**
- Severity: Moderate
- Impact: Source code exposure risk for non-Chromium based browser users
- Description: Users' source code may be stolen when accessing a malicious website using non-Chromium based browsers

2. **GHSA-4v9v-hfq4-rm2v**
- Severity: Moderate
- Impact: Source code exposure risk
- Description: Users' source code may be stolen when accessing a malicious website

**Technical Details:**
The vulnerabilities are present in webpack-dev-server versions <=5.2.0. While our direct dependency on webpack-dev-server is at ^5.2.2 (which is not vulnerable), there may be a nested dependency through @wordpress/scripts that still uses a vulnerable version.

**Proposed Solution:**
1. Update the affected packages:
`npm audit fix --force`

Note: This will install @wordpress/scripts@19.2.4, which is a breaking change from our current version (30.20.0).

**Risk Assessment:**
- These vulnerabilities only affect development environments where webpack-dev-server is running
- Production builds are not affected
- The vulnerability requires user interaction with a malicious website
- Impact is limited to potential source code exposure

**Required Actions:**
1. Review the breaking changes between @wordpress/scripts v30.20.0 and v19.2.4
2. Create a development branch for testing
3. Run the update with detailed testing of all build and development processes
4. Document any required changes to maintain compatibility

**Testing Requirements:**
1. Verify all npm scripts continue to function:
- build
- build:production
- lint:css
- fix:css
- lint:js
- fix:js
- start
- test:unit

**Labels:**
- security
- dependencies
- breaking-change

**Priority:** Medium
(Based on moderate severity and development-only impact)

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.