Skip to content
yceffort
PostsSeriesTagsAbout🧪 Research
KO

Tweaks

theme
accent palette
film grain
minimal mode
04 POSTS

Security 1

  • â—† OG Scraping Server Design Notes · Part 2
    #security#nodejs#backend

    Building an OG Scraping Server in Node.js (2): How SSRF Gets Through

    A feature where the server opens a URL the user handed it has the textbook conditions for SSRF written into its spec. Six ways a whitelist gets bypassed first, then five defensive principles that block them, all actually run on Node. Strip IPv4-mapped by hand and it gets through in hex notation, undici lookup hook is never called when the host is an IP literal, and URL.hostname keeps the brackets on an IPv6 literal. The final post of a two-part design note on OG scraping servers.

    2026-08-22·25 min read
  • #security#ci-cd#npm

    The TanStack npm Supply Chain Attack: Why pull_request_target Is Dangerous

    Analysis of the @tanstack/* supply chain incident. The risks of pull_request_target, GitHub Actions cache, and OIDC trusted publishers, and how to defend against them.

    2026-05-16·24 min read
  • #nodejs#security#javascript

    The Pitfalls of Node.js vm Module: Why It's Not a Sandbox

    A preview of section 5.2 (Pitfalls of the vm Module) from the upcoming Node.js Deep Dive book.

    2026-02-27·14 min read
  • #security#nextjs#react

    It's a React vulnerability, so why do I have to upgrade Next.js?

    CVE-2025-55182, CVE-2025-55184, CVE-2025-55183, and the React hidden inside Next.js

    2025-12-12·19 min read
mailMail icongithubtwitter
yceffort
•
© 2026
•
https://yceffort.kr