Collected research
Remote code execution in cdnjs of Cloudflare
The cdnjs library update server extracted npm tarballs and copied files out of Git repositories without sanitizing paths or handling symlinks safely, so a published package could traverse out of its directory or link to arbitrary files. Reading the process environment recovered GitHub and Cloudflare Workers KV tokens that would have allowed tampering with a CDN used by 12.7% of websites.
Record
- Researcher
- RyotaK
- Published by
- blog.ryotak.net
- Date
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of RyotaK, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .