Medium · 4.9 Node.js & npm GHSA-jmg2-rcxh-w8q3 CVE-2026-61782
Unauthenticated HTTP API in @rsdoctor/rspack-plugin Exposes Source Code and Build Metadata
A vulnerability in @rsdoctor/rspack-plugin allowed any network-adjacent or remote attacker to retrieve compiled JavaScript source code and build configuration via an unauthenticated HTTP endpoint. The issue is fixed in version 1.5.16.
AI summary
A security issue has been disclosed in @rsdoctor/rspack-plugin, a build analyzer component used with Rspack-based projects. The default report server started by the plugin exposed sensitive build data through an unauthenticated HTTP endpoint, allowing attackers on the network or, in some configurations, the broader internet, to extract compiled application source code and build configuration without any credentials. The issue is tracked as CVE-2026-61782 (GHSA-jmg2-rcxh-w8q3) and has been fixed in version 1.5.16.
What happened
Prior to version 1.5.16, the Rsdoctor report HTTP server started by @rsdoctor/rspack-plugin bound to all network interfaces (0.0.0.0) by default. It served a POST /api/data/key endpoint without any authentication and with a wildcard CORS policy (Access-Control-Allow-Origin: *). As a result, any network-adjacent or remote attacker could send a single unauthenticated request to this endpoint to retrieve the full source code of all compiled JavaScript modules (moduleCodeMap), the serialized build configuration (configs), error details, and other sensitive build metadata.
Technical cause
The root cause is twofold: the server listens on 0.0.0.0, making it reachable beyond the local machine, and the data-retrieval endpoint lacks authentication while also permitting cross-origin requests from any origin due to the wildcard CORS header. Combined, these weaknesses allow unauthorized actors to pull sensitive build data without needing to be on the same host or to present any credentials. This is classified as CWE-200, Exposure of Sensitive Information to an Unauthorized Actor.
Why it matters
The exposed data includes the complete source code of compiled JavaScript modules and build configuration details. Depending on the project, this could reveal proprietary application logic, internal architecture, or configuration values that were not intended to be publicly accessible. Because the report server is enabled by default in non-CI environments and requires no special configuration to trigger exposure, developers may be affected without realizing the server was reachable externally.
Who is affected
Any project using @rsdoctor/rspack-plugin in a version up to and including 1.5.15, where the default Rsdoctor report server is active in a non-CI environment, is potentially affected. Exposure depends on whether the host running the build process is reachable from untrusted networks.
Affected versions
@rsdoctor/rspack-plugin versions up to and including 1.5.15 are affected. Version 1.5.16 contains the fix.
Fixes and mitigation
The vendor has released version 1.5.16 of @rsdoctor/rspack-plugin, which patches the unauthenticated endpoint and the default network binding behavior described above.
Recommended action
Upgrade @rsdoctor/rspack-plugin to version 1.5.16 or later. Until the upgrade is applied, avoid running the Rsdoctor report server on hosts reachable from untrusted networks, and restrict network access to the build host where possible.
PatchBriefing score
4.9 / 10 · Medium
Official CVSS: 7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Why this score
The vulnerability carries a CVSS base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N), reflecting network-exploitable access with low attack complexity, no privileges or user interaction required, and a high confidentiality impact with no effect on integrity or availability. The PatchBriefing score of 4.9 incorporates the CVSS base score along with the fact that the flaw is unauthenticated and remotely exploitable without user interaction, while no known exploitation, public exploit code, or EPSS-driven elevated risk has been observed, and a fix is already available.
Affected versions
- @rsdoctor/rspack-plugin <= 1.5.15
- vulnerable
- ≥ 1.5.16
- patched
Reported fixes
The vendor has released version 1.5.16 of @rsdoctor/rspack-plugin, which patches the unauthenticated endpoint and the default network binding behavior described above.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
GitHub Advisory Database database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email