Web Hack List

Collected research

Remote code execution in cdnjs of Cloudflare

The cdnjs library update server extracted npm tarballs and copied files out of Git repositories without sanitizing paths or handling symlinks safely, so a published package could traverse out of its directory or link to arbitrary files. Reading the process environment recovered GitHub and Cloudflare Workers KV tokens that would have allowed tampering with a CDN used by 12.7% of websites.

Record

Researcher
RyotaK
Published by
blog.ryotak.net
Date
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of RyotaK, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .