coder / coder/code-server

Security: Multiple vulnerabilities found via Snyk Code Analysis (XSS, Path Traversal, ReDoS, Open Redirect)

Aperta
#7,737 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub
bug security
Lingua principale
TypeScript
Stelle
79.3k
Fork
6.8k
Merge medio
2g 6h
PR unite (30g)
41

Descrizione

## Summary

Snyk Code Analysis identified 65 issues across 92 analyzed files in code-server. The High severity findings affect production deployments.

## High Severity (7 issues)

### Cross-site Scripting (XSS) — CWE-79, Score 807
- `src/node/routes/errors.ts` line 56
- `src/node/routes/login.ts` lines 68, 119

User-controlled input may be rendered without proper HTML escaping in error and login responses.

### Path Traversal — CWE-23, Score 804
- `src/node/routes/vscode.ts` lines 149, 219

User-supplied path components may allow reading files outside the intended directory.

### Regular Expression Denial of Service (ReDoS) — CWE-400, Score 752
- `src/node/routes/domainProxy.ts` line 46

A regex pattern may cause catastrophic backtracking with crafted input.

## Medium Severity (14 issues)

### Open Redirect — CWE-601, Score 557
- `src/node/routes/login.ts` lines 62, 99
- `src/node/routes/index.ts` line 94

### Allocation of Resources Without Limits — CWE-770, Score 555
- `src/node/routes/errors.ts` line 37
- `src/node/routes/vscode.ts` line 213

### Information Exposure via X-Powered-By — CWE-200, Score 554
- `src/node/app.ts` line 70

### Sensitive Cookie Without Secure/HttpOnly Flags — CWE-614/CWE-1004, Score 402
- `src/node/routes/login.ts` line 96

## Low Severity (44 issues)

Primarily in test files (hardcoded passwords, cleartext HTTP). Not production concerns.

## Reproduction

Scanned with Snyk Code Analysis on code-server main branch (commit near v4.112.0).

## Suggested Fixes

- XSS: HTML-encode user input before rendering in error/login templates
- Path Traversal: Resolve and validate paths against intended root directory
- ReDoS: Simplify or replace the vulnerable regex pattern
- Open Redirect: Validate redirect URLs against an allowlist
- X-Powered-By: Disable with `app.disable('x-powered-by')`
- Cookie flags: Add `Secure` and `HttpOnly` to session cookies

Happy to submit PRs for any of these if the team confirms the approach.

Guida per i contributori

Apri la guida per i contributori

Valutazione

Questa issue non è ancora stata valutata.

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.