Skip to content

fix: fix an unlikely JSON injection security vulnerability - #4928

Merged
TomOnTime merged 1 commit into
mainfrom
tlim_bobbytables
Sep 22, 2026
Merged

TomOnTime merged 1 commit into
mainfrom
tlim_bobbytables

Conversation

@TomOnTime

@TomOnTime TomOnTime commented Sep 22, 2026 •

Copy link
Copy Markdown
Collaborator

Issue

An MX record with the target mx1.example.com"), A("attacker-controlled", "203.0.113.66 will force dnscontrol get-zone --format js to generate a dnsconfig.js file with an extra A record.

Resolution

JSON-quote all fields.

Risk

Low.

  • The attacker would have to access your portal... at which point they could just insert the record with their mouse.
  • If the attacker is the DNS service provider, they could serve evil records without you knowing.
  • Before you are powned.... every dnscontrol preview would highlight the change.
  • Before you are powned.... every dnscontrol push would undo their change.
  • While you are being powned... after you run dnscontrol get-zone --format js you are forced to edit the output (it isn't perfect, just "a good first draft") and you'd probably notice this situation, especially if you run dnscontrol fmt

Alas, stranger attacks have happened. Therefore, we're fixing this.

CC @cafferata who did the work, I'm just merging the PR.

@TomOnTime TomOnTime changed the title fix: Fix an unlikely JSON injection security vulnerability fix: fix an unlikely JSON injection security vulnerability Sep 22, 2026
@TomOnTime
TomOnTime merged commit 1e05eea into main Sep 22, 2026
40 of 41 checks passed
@TomOnTime
TomOnTime deleted the tlim_bobbytables branch September 22, 2026 13:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant