microsoft / microsoft/TypeScript
Wildcard package.json exports auto-import path does not apply traversal containment checks
还没有人认领这个 Issue。
- 主要语言
- Go
- 星标
- 111k
- 派生
- 14.3k
- 平均合并
- 2 天 4 小时
- 30 天内合并 PR
- 132
描述
### Demo Repo
https://github.com/zainnadeem786/typescript-autoimport-traversal-poc
### Which of the following problems are you reporting?
Something else more complicated which I'll explain in more detail
### Demonstrate the defect described above with a code sample.
import { LEAKED_SECRET_SYMBOL } from "evil-pkg/secret";
### Run `tsc --showConfig` and paste its output here
{
"compilerOptions": {
"module": "nodenext",
"moduleResolution": "nodenext",
"target": "es2022",
"strict": true
},
"files": [
"./src/app.ts"
]
}
### Run `tsc --traceResolution` and paste its output here
======== Resolving module 'evil-pkg/secret' ========
Module name 'evil-pkg/secret' was not resolved.
======== Module name 'evil-pkg/secret' was not resolved. ========
### Paste the `package.json` of the *importing* module, if it exists
{
"name": "victim-project",
"private": true,
"type": "module",
"dependencies": {
"evil-pkg": "1.0.0"
}
}
### Paste the `package.json` of the *target* module, if it exists
{
"name": "evil-pkg",
"version": "1.0.0",
"exports": {
"./*": "./../../private/*.ts"
}
}
### Any other comments can go here
This is not a standard runtime/build-time module resolution mismatch. I selected “Something else more complicated” because the issue is specifically in tsserver package-json auto-import indexing.
Normal module resolution rejects the traversal export target:
```text
resolveModuleName("evil-pkg/secret"): undefined
```
However, the tsserver auto-import provider still indexes a file outside the package boundary:
```text
D:/TypeScript/msrc-tsserver-autoimport-traversal-poc/victim-project/private/secret.ts
```
The relevant behavior appears to be in `loadEntrypointsFromTargetExports()`, where the wildcard export target is expanded and passed to `readDirectory()` without applying the same traversal/containment validation used by normal export resolution.
The minimal reproduction repository includes a script that demonstrates:
1. normal module resolution rejects the traversal target
2. auto-import indexing still includes the out-of-package file
3. completion details expose the out-of-package symbol metadata
This was originally reviewed by MSRC and treated as defense-in-depth hardening rather than a serviced security vulnerability. MSRC recom
mended opening a GitHub issue so the TypeScript team can consider applying the same `../`, `./`, and `node_modules` containment checks to the wildcard branch.
贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
调研方向
从 tsserver 自动导入提供程序中的 loadEntrypointsFromTargetExports() 开始,将其通配符导出处理与正常的模块解析进行比较。运行链接的最小复现,以观察遍历目标的索引和 completion 元数据。当通配符导出拒绝 package 边界之外的目标,且没有任何 package 外部的 symbol 被索引时,即视为完成。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- typescript
- 领域
- security, tooling
- Issue 类型
- 缺陷
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 活跃度
- 冷清
- 描述清晰度
- 基本清楚
- 新手友好度
- 52/100