Fix ReDoS in mu-plugins loader path regex - #4254
Merged
Merged
Conversation
The regex parsing $studio_mu_plugins_dir had ambiguous alternatives that allowed exponential backtracking on inputs with many backslashes. Exclude backslash from the catch-all branch so the alternatives are mutually exclusive. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Collaborator
📊 Performance Test ResultsComparing 4bb49ca vs trunk app-size
site-editor
site-startup
Results are median values from multiple test runs. Legend: 🟢 Improvement (faster) | 🔴 Regression (slower) | ⚪ No change (<50ms diff) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Related issues
js/redos, CWE-1333, high severity)How AI was used in this PR
Claude Code fetched the code scanning alert, identified the ambiguous regex branch causing exponential backtracking, applied the fix, and verified correctness and timing. All human-reviewed.
Proposed Changes
The regex that reads the mu-plugins directory path back out of the generated loader plugin (
$studio_mu_plugins_dir = '...') had ambiguous alternatives: its catch-all branch[^']also matched a lone backslash, overlapping with the\\and\'escape branches. A path containing many consecutive backslashes could therefore be matched multiple ways, triggering catastrophic (exponential) backtracking — a ReDoS. In practice this is reached when Studio parses an existing native-PHP loader file, so a malformed/crafted loader path could hang the process.The fix excludes backslash from the catch-all branch (
[^\\']), making the three alternatives mutually exclusive while still matching exactly what PHP single-quote escaping produces. No behavior change for valid paths.Testing Instructions
npm test -- packages/common/lib/tests/mu-plugins.test.ts— all 12 tests pass.Pre-merge Checklist