Dyad RCE Vulnerability Summary
A critical security vulnerability has been discovered that affected Dyad v0.19.0 and earlier versions that allows attackers to execute arbitrary code on users' systems. The vulnerability affects the application's preview window functionality and can bypass Docker container protections.
How it Works
The vulnerability occurs when malicious content is displayed in Dyad's preview window. An attacker can craft web content that automatically executes when the preview loads. The malicious content can break out of the application's security boundaries and gain control of the system.
Attack Scenarios
Attackers could exploit this vulnerability through:
- Malicious templates: Distributing compromised templates through Dyad's community templates
- Indirect prompt injection: Embedding malicious content in external sources that users might reference
Impact
- Remote Code Execution: Attackers can run arbitrary commands on the victim's computer
- Container Escape: The vulnerability bypasses Docker protections, affecting the host system even when Dyad runs in containers
Who's Affected
Any user of Dyad v0.19.0 or earlier who previews web applications containing untrusted content. This includes users who import community templates or work with external content sources.
Remediation
This has been fixed in Dyad v0.20.0 and later. Please upgrade to the latest Dyad version as soon as possible: https://www.dyad.sh/download.
Acknowledgements
We thank @jackfromeast and @Suuuuuzy for their responsible disclosure of this vulnerability, including a proof-of-concept demonstration, and for their guidance on the remediation.
Dyad RCE Vulnerability Summary
A critical security vulnerability has been discovered that affected Dyad v0.19.0 and earlier versions that allows attackers to execute arbitrary code on users' systems. The vulnerability affects the application's preview window functionality and can bypass Docker container protections.
How it Works
The vulnerability occurs when malicious content is displayed in Dyad's preview window. An attacker can craft web content that automatically executes when the preview loads. The malicious content can break out of the application's security boundaries and gain control of the system.
Attack Scenarios
Attackers could exploit this vulnerability through:
Impact
Who's Affected
Any user of Dyad v0.19.0 or earlier who previews web applications containing untrusted content. This includes users who import community templates or work with external content sources.
Remediation
This has been fixed in Dyad v0.20.0 and later. Please upgrade to the latest Dyad version as soon as possible: https://www.dyad.sh/download.
Acknowledgements
We thank @jackfromeast and @Suuuuuzy for their responsible disclosure of this vulnerability, including a proof-of-concept demonstration, and for their guidance on the remediation.