Skip to content

esbuildsandbox, the leak the engine found - #17

Merged
tannevaled merged 1 commit into
mainfrom
the-leak-the-engine-found
Sep 26, 2026
Merged

tannevaled merged 1 commit into
mainfrom
the-leak-the-engine-found

Conversation

@tannevaled

Copy link
Copy Markdown
Contributor

Three modules, two in the table. The missing one is the security fix.

Bundling a page's own <script type="module"> graph through esbuild looks sandboxed: every import in your own tests goes through your OnResolve/OnLoad plugin. A glob dynamic import does not — the bundler expands it by walking ResolveDir on the real filesystem through its internal resolver, following symlinks, with the plugin API never seeing it. "/" is a common default for that field.

A module that exists because somebody hit that is exactly the one worth finding before hitting it, and it was on no page of the organisation that found it.

🤖 Generated with Claude Code

Three modules, two in the table. The missing one is the security fix: bundling a
page's own script graph through esbuild looks sandboxed because every import in
your tests goes through your plugin, and a glob dynamic import does not — the
bundler walks ResolveDir on the real filesystem, following symlinks, with the
plugin API never seeing it.

A module that exists because somebody hit that is the one worth finding before
hitting it, and it was on no page.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@tannevaled
tannevaled merged commit 3faf2d2 into main Sep 26, 2026
1 check passed
@tannevaled
tannevaled deleted the the-leak-the-engine-found branch September 26, 2026 16:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant