Path traversal (CWE-22/CWE-73): event-image, branding (logo/favicon), and event-attachment uploads built the saved filename from the client-supplied original filename with no sanitization, and multer's diskStorage joins that straight into the destination path. A crafted filename containing `../` sequences could write the uploaded file anywhere the server process has write access — reachable by any supervisor-level account, and briefly pre-auth via the branding uploads during initial /setup. Filenames are now always server- generated (random bytes + validated extension); the original name is kept only as display metadata. Dependencies: express-rate-limit was declared only at the repo root despite being required directly by backend/src/index.js, so a plain `cd backend && npm install` (per the deployment doc) would never install it — moved it into backend/package.json. Bumped next off a version affected by a critical unauthenticated RCE (React Flight protocol) and switched it from an exact pin to a caret range so future patches install automatically. Bumped multer/nodemailer/jsonwebtoken/ uuid to patched versions, with an override forcing the vulnerable nested uuid inside exceljs and the vulnerable postcss bundled inside next to the patched versions too. `npm audit` is now clean (0 vulnerabilities) across root, backend, and frontend. Hardening: jwt.verify() now pins algorithms: ['HS256'] instead of trusting the token header; /uploads now serves with a restrictive CSP and X-Content-Type-Options: nosniff so an uploaded SVG containing <script> can't execute if opened directly. Verified: backend's Jest suite passes, the backend boots and serves real requests on the bumped deps, and `next build` compiles/type- checks cleanly on the bumped frontend deps. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01CSWFWQsjTc9GyffPiXEDQT
47 lines
1.2 KiB
JSON
47 lines
1.2 KiB
JSON
{
|
|
"name": "event-management-backend",
|
|
"version": "1.10.0",
|
|
"description": "Event Management System Backend",
|
|
"main": "src/index.js",
|
|
"scripts": {
|
|
"start": "node src/index.js",
|
|
"dev": "nodemon src/index.js",
|
|
"test": "jest",
|
|
"postinstall": "prisma generate",
|
|
"prisma:generate": "prisma generate",
|
|
"prisma:deploy": "prisma migrate deploy && prisma generate",
|
|
"prisma:status": "prisma migrate status",
|
|
"prisma:reset": "prisma migrate reset --force",
|
|
"migrate:env-to-db": "node scripts/migrate-env-to-db.js",
|
|
"migrate:env-to-db:dry": "node scripts/migrate-env-to-db.js --dry-run"
|
|
},
|
|
"dependencies": {
|
|
"@prisma/client": "^5.4.2",
|
|
"@sentry/node": "^10.71.0",
|
|
"axios": "^1.11.0",
|
|
"bcryptjs": "^2.4.3",
|
|
"cors": "^2.8.5",
|
|
"dotenv": "^16.3.1",
|
|
"exceljs": "^4.4.0",
|
|
"express": "^4.18.2",
|
|
"express-rate-limit": "^8.6.2",
|
|
"ics": "^3.12.0",
|
|
"jsonwebtoken": "^9.0.3",
|
|
"multer": "^2.2.0",
|
|
"node-fetch": "^2.7.0",
|
|
"nodemailer": "^9.0.6",
|
|
"pdfkit": "^0.17.1",
|
|
"qrcode": "^1.5.4",
|
|
"raw-body": "^3.0.0",
|
|
"uuid": "^11.1.1"
|
|
},
|
|
"devDependencies": {
|
|
"jest": "^30.4.2",
|
|
"nodemon": "^3.0.1",
|
|
"prisma": "^5.4.2"
|
|
},
|
|
"overrides": {
|
|
"uuid": "^11.1.1"
|
|
}
|
|
}
|