nocobase-prototype-repro

Fail

Audited by Socket on Jun 15, 2026

6 alerts found:

Securityx5Malware
SecurityMEDIUM
references/template-library/heroBanner.md
SecurityMEDIUM
references/template-library/progressGoal.md
SecurityMEDIUM
references/template-library/kpiStat.md
SecurityMEDIUM
references/template-library/conditionCards.md
SecurityMEDIUM
references/template-library/conditionMenu.md
MalwareHIGH
references/template-library/customFilter.md

This module is security-critical because it implements an unsandboxed 'js' mode that executes option-provided JavaScript via new Function with access to ctx. That creates an arbitrary runtime code execution pathway and then applies the result to multiple target data queries via filter-group injection and refresh. If an attacker can influence $p.options (directly or via compromised configuration/templates), this represents a strong supply-chain and runtime compromise risk.

Confidence: 60%Severity: 90%
Audit Metadata
Analyzed At
Jun 15, 2026, 12:41 AM
Package URL
pkg:socket/skills-sh/nocobase%2Fskills%2Fnocobase-prototype-repro%2F@a80fdd07a785ab49afe8e1a0e06af25dacb94c947afc8cae657a8ecbe6651ad7
Security Audit — socket — nocobase-prototype-repro