GHSA-j3w7-9qc3-g96p

Suggest an improvement
Source
https://github.com/advisories/GHSA-j3w7-9qc3-g96p
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-j3w7-9qc3-g96p/GHSA-j3w7-9qc3-g96p.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-j3w7-9qc3-g96p
Aliases
Published
2025-10-23T16:01:35Z
Modified
2025-10-23T20:37:07Z
Severity
  • 7.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U CVSS Calculator
Summary
Kottster app reinitialization can be re-triggered allowing command injection in development mode
Details

Impact

Development mode only. Kottster contains a pre-authentication remote code execution (RCE) vulnerability when running in development mode.

The vulnerability combines two issues:

  1. The initApp action can be called repeatedly without checking if the app is already initialized, allowing attackers to create a new root admin account and obtain a JWT token
  2. The installPackagesForDataSource action uses unescaped command arguments, enabling command injection

An attacker with access to a locally running development instance can chain these vulnerabilities to:

  • Reinitialize the application and receive a JWT token for a new root account
  • Use this token to authenticate
  • Execute arbitrary system commands through installPackagesForDataSource

Production deployments were never affected.

Patches

Fixed in v3.3.2.

Specifically, @kottster/server v3.3.2 and @kottster/cli v3.3.2 address this vulnerability.

We recommend developers using earlier versions of @kottster/server and @kottster/cli update all the core packages to latest release:

npm install @kottster/common@latest @kottster/cli@latest @kottster/server@latest @kottster/react@latest

Workarounds

  • Do not expose development servers to public networks or untrusted users
  • Use production mode for any deployment accessible from outside trusted environments

Credit

We sincerely thank Jeongwon Jo (@P0cas) from RedAlert for discovering and responsibly disclosing this vulnerability.

Database specific
{
    "cwe_ids":  [
        "CWE-284",
        "CWE-78"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2025-10-23T16:01:35Z",
    "nvd_published_at":  "2025-10-23T17:15:40Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / @kottster/server

Package

Name
@kottster/server
View open source insights on deps.dev
Purl
pkg:npm/%40kottster/server

Affected ranges

Type
SEMVER
Events
Introduced
3.2.0
Fixed
3.3.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/10/GHSA-j3w7-9qc3-g96p/GHSA-j3w7-9qc3-g96p.json"