dengliming opened a new issue, #613: URL: https://github.com/apache/shenyu-dashboard/issues/613
## Description Plugin-handle definitions (`plugin_handle.ext_obj.rule`) are entered through the PluginHandle page and stored on the server. When a selector/rule/plugin form is rendered, the dashboard builds the antd validation `pattern` with `eval(checkRule)`. Anyone with `system:pluginHandler:edit` permission (or anyone who can write to the database) can store an arbitrary JavaScript expression that then runs in the browser of every administrator who opens the corresponding editor – a stored-XSS equivalent. A non-regex string also throws during render and crashes the page. ## Location (Lines refer to `master @ 83969a5`.) - `src/routes/Plugin/Common/Selector.js:785,1556` - `src/routes/Plugin/Common/CommonRuleHandle.js:105` - `src/routes/Plugin/Discovery/ProxySelectorModal.js:394,627` - `src/routes/System/Plugin/AddModal.js:176` - `src/routes/System/NamespacePlugin/AddModal.js:183` ## Impact Privilege escalation from "can edit plugin handles" to "can run code as any admin" (token is kept in `sessionStorage`); also a page crash for any malformed rule string. ## Suggested fix Replace `eval(checkRule)` with `new RegExp(checkRule)` wrapped in `try/catch` (fall back to no pattern on failure). If rules are stored in `/regex/flags` form, parse them explicitly instead of evaluating. ## Related existing None -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
