Skip to content

fix(client): secure postMessage communications and close iframe injection vector - #1310

Open
vibemasshq-dev wants to merge 1 commit into
codesandbox:mainfrom
vibemasshq-dev:fix-postmessage-security
Open

vibemasshq-dev wants to merge 1 commit into
codesandbox:mainfrom
vibemasshq-dev:fix-postmessage-security

Conversation

@vibemasshq-dev

Copy link
Copy Markdown

What does this PR do?

This PR hardens the postMessage communication layer in sandpack-client/src/clients/node/index.ts and inject-scripts/historyListener.ts.

While reviewing the event listeners, I noticed a critical nuance in how messages are handled:

  1. Inbound Injection Vector: Although messageChannelId provides a good security token for most dispatched events, the PREVIEW_LOADED_MESSAGE_TYPE check in globalListeners lacks both channel ID and origin validation. Any malicious page that knows this public event type could send it to the Sandpack instance and trigger injectScriptToIframe. This PR scopes that listener strictly to the expected bundlerURL origin.
  2. Outbound Data Leakage: In the dispatch method, urlback and urlforward messages are broadcast to the iframe using a wildcard * target origin. If the preview iframe were somehow navigated to an unexpected origin, it would receive these internal navigation commands. This PR scopes those outbound messages specifically to new URL(this.iframePreviewUrl).origin.

Architecture Heads-Up 🏗️

While investigating the messaging layer, I was looking through the runtime client folder and noticed that sandpack-client/src/clients/runtime/index.ts is growing into quite a monolithic module (~800+ lines handling everything from bundler compilation to iframe management).

As Sandpack continues to scale, it might be worth decomposing that core runtime client into smaller, more focused sub-modules (e.g., separating the message handlers from the state manager) to improve testability and make onboarding easier for future contributors!

Best,
@vibemasshq-dev

@codesandbox

codesandbox Bot commented Sep 2, 2026

Copy link
Copy Markdown

Review or Edit in CodeSandbox

Open the branch in Web Editor • VS Code • Insiders

Open Preview

@vercel

vercel Bot commented Sep 2, 2026

Copy link
Copy Markdown

@vibemasshq-dev is attempting to deploy a commit to the CodeSandbox Team on Vercel.

A member of the Team first needs to authorize it.

@codesandbox-ci

codesandbox-ci Bot commented Sep 2, 2026

Copy link
Copy Markdown

This pull request is automatically built and testable in CodeSandbox.

To see build info of the built libraries, click here or the icon next to each commit SHA.

@vibemasshq-dev

Copy link
Copy Markdown
Author

Hello, any review on this? Thank you

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant