{"id":"GHSA-8g98-m4j9-qww5","aliases":[],"url":"https://o3.security/vulnerability/GHSA-8g98-m4j9-qww5","summary":"Taylored webhook validation vulnerabilities","details":"### Critical Security Advisory for Taylored npm package v7.0.7 - tag 7.0.5\n\n#### Summary\n\nA series of moderate to high-severity security vulnerabilities have been identified specifically in version **7.0.7 of \\`taylored\\`**. These vulnerabilities reside in the \"Backend-in-a-Box\" template distributed with this version. They could allow a malicious actor to read arbitrary files from the server, download paid patches without completing a valid purchase, and weaken the protection of encrypted patches.\n\n**All users who have installed or generated a \\`taysell-server\\` using version 7.0.7 of \\`taylored\\` are strongly advised to immediately upgrade to version 7.0.8 (or later) and follow the required mitigation steps outlined below.** Versions prior to 7.0.7 did not include the Taysell functionality and are therefore not affected by these specific issues.\n\n#### Vulnerabilities Patched in v7.0.8\n\nVersion 7.0.8 addresses the following issues found in the v7.0.7 template:\n\n1.  **Path Traversal in Patch Download:** The patch download endpoint did not properly sanitize the user-provided \\`patchId\\`. An attacker could have crafted a request with path traversal sequences (e.g., \\`../../etc/passwd\\`) to read arbitrary files from the server's filesystem. The \\`patchId\\` is now sanitized to ensure only files within the intended patches directory can be accessed.\n2.  **Missing PayPal Webhook Validation:** The server endpoint did not cryptographically verify incoming payment notifications, allowing an attacker to spoof a purchase and gain unauthorized access to patches.\n3.  **Purchase Token Replay Vulnerability:** A legitimate purchase token could be reused indefinitely. The system now correctly invalidates tokens after their first use.\n4.  **Insufficient PBKDF2 Iterations:** The key derivation function used an insufficient number of iterations, making encrypted patches more susceptible to brute-force attacks. This has been strengthened.\n\n### Required Actions\n\nTo fix these vulnerabilities, users of version **7.0.7** must **upgrade the \\`taylored\\` tool and regenerate their \\`taysell-server\\` instance**.\n\nPlease follow these steps carefully:\n\n1.  **Upgrade to the Secure Version of \\`taylored\\`:**\n    Open your terminal and run the following command to install the latest version:\n    \\`\\`\\`bash\n    npm install -g taylored@latest\n    \\`\\`\\`\n    Verify that you have version 7.0.8 or later.\n\n2.  **Remove the Vulnerable Backend:**\n    Navigate to the project directory where you previously generated the backend with v7.0.7 and **completely delete the old \\`taysell-server\\` directory**.\n    \\`\\`\\`bash\n    # Back up any customizations if necessary\n    rm -rf taysell-server\n    \\`\\`\\`\n\n3.  **Generate the New, Secure Backend:**\n    From the same directory, run the \\`setup-backend\\` command again using the upgraded \\`taylored\\` tool. This will create a new \\`taysell-server\\` directory with the patched, secure code.\n    \\`\\`\\`bash\n    taylored setup-backend\n    \\`\\`\\`\n    Follow the prompts and enter your PayPal credentials and server configuration. **Using a new, strong, and unique \\`PATCH_ENCRYPTION_KEY\\` is highly recommended.**\n\n4.  **Recreate and Re-upload Commercial Patches:**\n    Due to the cryptography improvements, **patches created with version 7.0.7 are not compatible with the new, secure backend**. You must recreate them:\n    * For each of your commercial patches, run the \\`taylored create-taysell\\` command again.\n    * Upload the new encrypted files (e.g., \\`patch-name.taylored.encrypted\\`) to the \\`patches/\\` directory of your new \\`taysell-server\\`.\n\n5.  **Launch the New Server:**\n    Start your new backend using Docker Compose:\n    \\`\\`\\`bash\n    cd taysell-server\n    docker-compose up --build -d\n    \\`\\`\\`\n\nFor questions or support, please refer to the official documentation or open an issue on our GitHub repository.\n\nThank you for your attention to this important update.","published":"2025-06-18T17:51:03Z","modified":"2025-06-18T17:51:03Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"taylored","fixedVersion":"7.0.8"}],"fix":{"url":"https://github.com/tailot/taylored/commit/57b7634391959dbbdb39b387ac4dc68157cd58a1","label":"tailot/taylored@57b7634"},"references":[{"type":"WEB","url":"https://github.com/tailot/taylored/security/advisories/GHSA-8g98-m4j9-qww5"},{"type":"WEB","url":"https://github.com/tailot/taylored/commit/57b7634391959dbbdb39b387ac4dc68157cd58a1"},{"type":"PACKAGE","url":"https://github.com/tailot/taylored"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-06-18T17:51:03Z"}}