Meta Vulnerabilities and Affected Products
Vulnerabilities associated with React Developer Tools Extension.
Products
Clear product- react-server-dom-parcel8 vulnerabilities
- react-server-dom-turbopack8 vulnerabilities
- react-server-dom-webpack8 vulnerabilities
- WhatsApp Business for Android2 vulnerabilities
- WhatsApp Business for iOS2 vulnerabilities
- WhatsApp for Android2 vulnerabilities
- WhatsApp for iOS2 vulnerabilities
- React Developer Tools Extension1 vulnerability
- React Server Components1 vulnerability
- tac_plus1 vulnerability
- Tacquito1 vulnerability
- WhatsApp cloud service1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
React Developer Tools extension Improper Authorization vulnerabilityThe React Developer Tools extension registers a message listener with window.addEventListener('message', <listener>) in a content script that is accessible to any webpage that is active in the browser. Within the listener is code that requests a URL derived from the received message via fetch(). The URL is not validated or sanitised before it is fetched, thus allowing a malicious web page to arbitrarily fetch URL’s via the victim's browser. | CVSS-v4.0 | EPSS0.467% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |