Skip to content

Security question: Why are data: URIs and file: URIs treated differently in your security policy? #53815

Closed
@eligrey

Description

@eligrey

Version

No response

Platform

No response

Subsystem

No response

What steps will reproduce the bug?

I noticed this bug report and asked @RafaelGSS why data: URIs are treated differently from file: URIs in the node.js security policy, as attackers can simply write to a file and then import it to achieve the same effect.

Rafael responded with the following, asking me to file an issue in this bug tracker instead of elaborating on X:

This vulnerability exposes a vulnerability according to Node.js threat model. I can expand more on that if you raise an issue.

But I certainly won't elaborate on a X thread :)

How often does it reproduce? Is there a required condition?

No response

What is the expected behavior? Why is that the expected behavior?

No response

What do you see instead?

N/A. I was requested by @RafaelGSS to use this issue reporting form.

Additional information

No response

Metadata

Metadata

Assignees

No one assigned

    Labels

    questionIssues that look for answers.securityIssues and PRs related to security.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions