rivet-actors
Audited by Socket on Oct 3, 2026
4 alerts found:
Securityx3AnomalyNo clear malware behavior is present. The hardcoded, predictable authentication tokens are a significant security weakness if this actor is deployed with these values, especially because the admin token grants moderation permissions. Message rendering safety depends on downstream consumers.
The code has a serious authentication flaw: any non-empty token is accepted as the same hard-coded user. This can permit unauthorized connections and should not be used for real authentication without proper token verification. No evidence of malware or data exfiltration appears in this fragment.
No clear malware is present. The token validation is a significant authentication flaw: any nonempty token can connect with a fixed member identity and send messages. Message content is stored and broadcast without sanitization, so consumers should handle it safely.
This module is a generic request-forwarding gateway. The primary security concern is that user-controlled route parameters are used to (a) select an actor instance and (b) construct the destination URL via new URL(actorPath, "http://actor"), potentially allowing absolute URL overrides, and (c) proxy the entire incoming request (c.req.raw) into the forwarded Request. No validation/allowlisting is present in the shown code. While there is no clear evidence of intentional malware, the relay/target-injection pattern presents a credible SSRF/open-proxy and sensitive-header forwarding risk depending on deployment and rivetkit actor.fetch semantics.