Skip to content

docs: ArcReel GHSA-5r36-2f3p-5q87 published, fixed in v0.31.0 (25th fix) - #158

Merged
elfrost merged 1 commit into
mainfrom
daily/2026-09-23-arcreel-resolved
Sep 23, 2026
Merged

elfrost merged 1 commit into
mainfrom
daily/2026-09-23-arcreel-resolved

Conversation

@elfrost

@elfrost elfrost commented Sep 23, 2026

Copy link
Copy Markdown
Owner

ArcReel published GHSA-5r36-2f3p-5q87 today, with the fix in v0.31.0 (#2601). That is fifty days after the private report and 48 after acceptance. The embargo has lifted, so the post now carries the full detail.

The fix differs from the proposal. Instead of dropping the CORS wildcard, it narrows the anonymous files route to media directories and extensions, judged on the resolved real path, with a uniform 404 and nosniff. That closes the content class for every anonymous reader, not only a cross-origin one.

Re-verified by differential on the verbatim decision logic: 14 non-media files served before, 0 after, 6/6 media still served, and no parse gap between the check and the file server. The symlink case was not run locally; the maintainers' own regression test covers it.

Self-correction published: the "you can find out" amplifier was overstated. Project identifiers carry 32 random bits, so the 404 oracle confirms a guess and cannot find one. The unchanged CORS default is recorded as hardening, not re-reported.

  • scan post: status resolved, update section, correction, timeline
  • index: outcome private → fixed, fix counters 24 → 25
  • fixed.md: ArcReel row added; counters had drifted (105 scans / 24)
  • scan log: resolution suffix on the 2026-08-04 entry
  • work-with-me: counters had drifted at 108 scans; now 109 / 25

🤖 Generated with Claude Code

The maintainers published the advisory on 2026-09-23, fifty days after the
private report and 48 after acceptance, with the fix in v0.31.0 (#2601).
The embargo has lifted, so the post now carries the full detail.

The shipped fix differs from the one proposed. Instead of dropping the CORS
wildcard, it narrows the anonymous files route to an allow-list of media
directories and extensions, judged on the resolved real path, with a uniform
404 and nosniff. That closes the content class for every anonymous reader,
not only a cross-origin one, and covers a stored-HTML/SVG impact the report
had not named.

Re-verified by differential on the verbatim decision logic (safe_join +
is_public_media_path): 14 non-media files served before, 0 after, 6/6 media
still served, and no parse gap between the check and the consumer. The
symlink case was not run locally (no symlink privilege, no Linux VM); the
maintainers' own regression test covers it.

The post also carries a self-correction: the "you can find out" amplifier
was overstated. The two 404 bodies do differ, but project identifiers carry
32 random bits (secrets.token_hex(4), present at the scanned commit too),
so the oracle confirms a guess and cannot find one. The unchanged CORS
default is recorded as hardening, not re-reported.

- scan post: status resolved, update section with detail, correction, timeline
- index: outcome private -> fixed, confirmed-fix counters 24 -> 25
- fixed.md: ArcReel row added; counters had drifted at 105 scans / 24 fixes
- scan log: resolution suffix on the 2026-08-04 entry
- work-with-me: counters had drifted at 108 scans; now 109 / 25

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@elfrost
elfrost merged commit d070452 into main Sep 23, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant