Skip to content

fix: add authentication check in server.js (CWE-306) - #461

Merged
luc-github merged 1 commit into
luc-github:3.1from
anupamme:fix-repo-esp3d-webui-cwe-306-mock-server-auth
Sep 26, 2026
Merged

luc-github merged 1 commit into
luc-github:3.1from
anupamme:fix-repo-esp3d-webui-cwe-306-mock-server-auth

Conversation

@anupamme

Copy link
Copy Markdown
Contributor

The Express server exposes /config and /command endpoints without any authentication middleware. The /command endpoint accepts arbitrary G-code commands via the 'cmd' query parameter and passes them directly to commandsQuery(). The /config endpoint exposes device configuration. Neither endpoint validates that the request is authenticated before processing. This was found by static analysis at config/server.js:102. I have not demonstrated an exploit against your deployment, so please judge it against your own threat model.

Reference: CWE-306

What changed

  • config/server.js

Verification

No automated check could be run against this repository, so this change is unverified beyond review. Please treat it as a suggestion.


Automated security fix by OrbisAI Security

Automated security fix generated by OrbisAI Security
@luc-github
luc-github merged commit eb10609 into luc-github:3.1 Sep 26, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants