Threats Tagged 'ghsa-79wm-x847-7cvg'
View all threats tagged with 'ghsa-79wm-x847-7cvg'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'ghsa-79wm-x847-7cvg'
Click on any threat for detailed analysis and mitigation recommendations
### Summary `npx claude-code-templates --studio` launches "Claude Code Studio", an Express HTTP server (`cli-tool/src/sandbox-server.js`, default port 3444) that binds to **all interfaces** (`0.0.0.0`), sets `Access-Control-Allow-Origin: *`, and requires **no authentication**. Two POST endpoints pass attacker-controlled request-body fields into `child_process.spawn(..., { shell: true })`. Because `shell: true` makes Node join the argv array into a single `sh -c` string, the fields are parsed by the shell and metacharacters execute. Any unauthenticated attacker who can reach the port — a malicious web page the developer visits, or anyone on the same LAN — can execute arbitrary OS commands on the developer's machine. ### Details In `cli-tool/src/sandbox-server.js`: - `app.listen(PORT, ...)` is called with no host argument, so the server listens on `0.0.0.0` / `::` (reachable from the LAN, not just localhost). - The CORS middleware sends `Access-Control-Allow-Origin: *` and answers the preflight `OPTIONS` for any origin, so a browser will deliver cross-origin POSTs to it. - There is no authentication on any endpoint. The vulnerable sinks: 1. `POST /api/execute` — the `prompt` body field flows into `executeLocalTask()`: ```js const child = spawn('claude', [finalPrompt], { /* ... */ shell: true }); The only validation on prompt is a length check (>= 10 chars). With shell: true, finalPrompt is interpreted by the shell. 2. POST /api/install-agent — the agentName body field: const child = spawn('npx', ['claude-code-templates@latest', '--agent', agentName, '--yes'], { /* ... */ shell: true }); 2. agentName is used unvalidated. (The same unsafe pattern is also reachable through /api/execute's agent field via checkAndInstallAgent().) Root cause: spawn(cmd, argsArray, { shell: true }) does not keep argsArray as separate argv entries — Node builds cmd + ' ' + argsArray.join(' ') and runs it via sh -c, so every element is subject to shell parsing. PoC # Victim npx claude-code-templates --studio # server on 0.0.0.0:3444 # Attacker (another LAN host, or a malicious web page fetch(), or locally) curl -s -X POST http://127.0.0.1:3444/api/execute \ -H 'Content-Type: application/json' \ --data '{"prompt":"aaaaaaaaaa; touch /tmp/CCT_RCE_PROOF","mode":"local"}' curl -s -X POST http://127.0.0.1:3444/api/install-agent \ -H 'Content-Type: application/json' \ --data '{"agentName":"x; touch /tmp/CCT_AGENT_PROOF #"}' ls -la /tmp/CCT_RCE_PROOF /tmp/CCT_AGENT_PROOF # both created => injected commands ran The aaaaaaaaaa padding satisfies the 10-char minimum, then ; (or $(...), or backticks) starts the injected command. claude/npx do not even need to be installed — the injected segment runs regardless. Confirmed at runtime on v1.28.13 (Node 22, Linux): both marker files were created, the server listened on *:3444, and an OPTIONS preflight from Origin: https://evil.example returned 200 with Access-Control-Allow-Origin: *. Impact Unauthenticated remote code execution (CWE-78) on any machine running --studio. Two reachability paths: - Drive-by: a developer running --studio who visits an attacker-controlled web page — the page's cross-origin fetch() (Content-Type application/json) passes the wildcard CORS preflight and delivers the POST, achieving RCE with no other interaction. - LAN: because the server binds 0.0.0.0, anyone on the same network (office, co-working space, public Wi-Fi) can hit port 3444 directly. Impact is full compromise of the developer's user account (arbitrary command execution with the developer's privileges): source code, SSH keys, cloud credentials, and .env secrets. Suggested fix - Remove shell: true from all three spawns so arguments stay discrete argv entries (kills the injection). - Validate agentName against a strict allowlist (^[A-Za-z0-9._/-]+$). - Bind to loopback only (app.listen(PORT, '127.0.0.1', ...)). - Replace the wildcard CORS with a same-origin allowlist and reject other origins. Join the discussion | CVE Database V5 | 09/04/2026, 08:51:25 UTC Added: 08/11/2026, 18:43:15 UTC |
Showing 1 to 1 of 1 result