Skip to content

fix: secure index.js (CWE-494) - #79

Merged
CodeDead merged 1 commit into
CodeDead:developmentfrom
anupamme:fix-repo-advanced-portchecker-updater-url-integrity-cwe-494
Sep 26, 2026
Merged

CodeDead merged 1 commit into
CodeDead:developmentfrom
anupamme:fix-repo-advanced-portchecker-updater-url-integrity-cwe-494

Conversation

@anupamme

Copy link
Copy Markdown
Contributor

The Updater component fetches update metadata from a remote server and extracts download URLs without cryptographic verification of the response integrity. The parseUpdate function extracts updateUrl, infoUrl, and version from the server response without verifying digital signatures, checksums, or certificate pinning. The affected code is src/utils/Updater/index.js:57. This change is the fix I would apply.

Reference: CWE-494

What changed

  • src/utils/Updater/index.js

Verification

No automated check could be run against this repository, so this change is unverified beyond review. Please treat it as a suggestion.

Regression test

The security boundary is maintained under adversarial input

Test
const { parseUpdate } = require('../../../src/utils/Updater/index.js');

describe("parseUpdate rejects unsigned/unverified update metadata", () => {
  const payloads = [
    // Exact exploit: attacker-controlled update URL without signature
    { updateUrl: 'https://evil.com/malware.exe', infoUrl: 'https://evil.com', version: '9.9.9' },
    // Boundary: empty/missing signature field with valid-looking URL
    { updateUrl: 'https://api.codedead.com/legit.exe', infoUrl: 'https://api.codedead.com', version: '1.0.0', signature: '' },
    // Valid input should include cryptographic verification (this test asserts it must reject without it)
    { updateUrl: 'https://api.codedead.com/update.exe', infoUrl: 'https://api.codedead.com/info', version: '2.0.0', checksum: 'sha256:abc123' },
  ];

  test.each(payloads)("rejects unverified metadata: %o", async (payload) => {
    // Security invariant: parseUpdate MUST NOT accept metadata lacking verified cryptographic signatures
    await expect(parseUpdate(payload)).rejects.toThrow();
  });
});

Automated security fix by OrbisAI Security

Automated security fix generated by OrbisAI Security
@CodeDead
CodeDead self-requested a review September 26, 2026 17:21
@CodeDead CodeDead added the enhancement Indicates new feature requests label Sep 26, 2026
@CodeDead
CodeDead changed the base branch from master to development September 26, 2026 17:21
@CodeDead

Copy link
Copy Markdown
Owner

Regardless of the HTTPS or not, the application is still dependent on trust. HTTPS certificates are easily obtained and don't stop malware attackers so this PR does very little to increase modern day security, but it also does not cause any harm to merge this.

@CodeDead CodeDead left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good to me.

@CodeDead
CodeDead merged commit 91640e1 into CodeDead:development Sep 26, 2026
2 of 12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement Indicates new feature requests

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants