v3.32.5
A security roll-up: hardens request-driven regexes against ReDoS, closes a path-traversal hole in the default payload storage, and clears outstanding CVE/CodeQL alerts in the UI.
What's Changed
- fix(core): prevent path traversal in
DummyPayloadStorage(#1651) — the default payload storage (used whenever no external S3/GCS storage is configured, so reachable in dev and default deployments) resolved caller-supplied paths againstpayloadDirwith no validation in bothupload()anddownload(), letting a../-style path read or write outside the payload directory. Paths now route through avalidateAndResolvePath()that normalizes, rejects residual.., and verifies the canonical path stays withinpayloadDir— mirroring the earlierMockExternalPayloadStoragefix (#723). Thanks @Denimworld12. - fix(security): replace the backtracking
${...}regex inParametersUtilswith a linear scanner (#1654) — the pattern that finds${...}expressions is applied to every string task parameter, including output returned by workers, and its match time grew polynomially with nesting depth (a ~3 KB string of${${...}}nested 1000 deep took over 30 seconds). Expressions are now located in a single brace-depth pass with identical semantics —$${escaping, nested expressions, and an unclosed expression swallowing the rest of the string all behave as before. Thanks @Naman-Gururani. (Fixes #1638) - fix(security): hoist
Patternand prevent ReDoS in the index query builders (#1648) —PostgresIndexQueryBuilderandSqliteIndexQueryBuildercompiled their parsing regex per call and used a pattern that could catastrophically backtrack on long all-letter search input. The pattern is now compiled once and hardened so malformed queries fail fast instead of hanging the search path. Thanks @jhaabhijeet864. (Fixes #1640) - fix(ui): resolve
wsto CVE-2024-37890 patched versions (#1672) — pins the transitivewsdev-dependency up via yarn resolutions (jsdom/ws→ 7.5.13,webpack-dev-server/ws→ 8.21.3), clearing the CVE alert. Thanks @nthmost. (Fixes #643) - fix(security): remove no-op identity replacement in the errorInspector path helper (#1660) — drops a
.replace(/\]\[/g, "][")that replaced][with itself (a CodeQLjs/identity-replacementalert); adjacent brackets like[0][1]are valid lodash nested-access syntax and were always passed through unchanged. Thanks @nthmost. (Fixes #1642)
Full Changelog: v3.32.4...v3.32.5