nocobase-prototype-repro
Fail
Audited by Socket on Jun 15, 2026
6 alerts found:
Securityx5MalwareSecurityreferences/template-library/heroBanner.md
MEDIUMSecurityMEDIUM
references/template-library/heroBanner.md
Securityreferences/template-library/progressGoal.md
MEDIUMSecurityMEDIUM
references/template-library/progressGoal.md
Securityreferences/template-library/kpiStat.md
MEDIUMSecurityMEDIUM
references/template-library/kpiStat.md
Securityreferences/template-library/conditionCards.md
MEDIUMSecurityMEDIUM
references/template-library/conditionCards.md
Securityreferences/template-library/conditionMenu.md
MEDIUMSecurityMEDIUM
references/template-library/conditionMenu.md
Malwarereferences/template-library/customFilter.md
HIGHMalwareHIGH
references/template-library/customFilter.md
This module is security-critical because it implements an unsandboxed 'js' mode that executes option-provided JavaScript via new Function with access to ctx. That creates an arbitrary runtime code execution pathway and then applies the result to multiple target data queries via filter-group injection and refresh. If an attacker can influence $p.options (directly or via compromised configuration/templates), this represents a strong supply-chain and runtime compromise risk.
Confidence: 60%Severity: 90%
Audit Metadata