{"id":"GHSA-96qw-h329-v5rg","summary":"Shakapacker has environment variable leak via EnvironmentPlugin that exposes secrets to client-side bundles","details":"### Summary\n\nSince 2017, the default webpack plugins have passed the entire `process.env` to `EnvironmentPlugin`. This pattern exposed ALL build environment variables to client-side JavaScript bundles whenever application code (or any dependency) referenced `process.env.VARIABLE_NAME`.\n\nThis is not a regression - the vulnerable code has existed since the original Webpacker implementation. No recent code change in Shakapacker triggered this issue.\n\n### Impact\n\nAny environment variable in the build environment that is referenced in client-side code (including third-party dependencies) is embedded directly into the JavaScript bundle. This includes:\n\n- `DATABASE_URL` - Database credentials\n- `AWS_SECRET_ACCESS_KEY` - AWS credentials  \n- `RAILS_MASTER_KEY` - Rails encrypted credentials key\n- `STRIPE_SECRET_KEY`, `TWILIO_AUTH_TOKEN` - Third-party API keys\n- Any other secrets present in the build environment\n\n**Severity**: Critical - secrets are exposed in publicly accessible JavaScript files.\n\n### Root Cause\n\nThe original code used:\n```javascript\nnew webpack.EnvironmentPlugin(process.env)\n```\n\nThis makes every environment variable available for substitution. If any code references `process.env.SECRET_KEY`, that value is embedded in the bundle.\n\n### Patches\n\nUpgrade to version 9.5.0 or later, which uses an allowlist approach that only exposes `NODE_ENV`, `RAILS_ENV`, and `WEBPACK_SERVE` by default.\n\n### Workarounds\n\nIf developers cannot upgrade immediately:\n1. Audit client-side code and dependencies for any `process.env.X` references to sensitive variables\n2. Remove sensitive variables from the build environment\n3. Override the default plugins with a custom webpack/rspack config using an explicit allowlist\n\n### Migration\n\nAfter upgrading, if client-side code needs access to specific environment variables:\n\n**Option 1: Use the `SHAKAPACKER_PUBLIC_` prefix (recommended)**\n```bash\n# Variables with this prefix are automatically exposed\nexport SHAKAPACKER_PUBLIC_API_URL=\"https://api.example.com\"\n```\n\n**Option 2: Use `SHAKAPACKER_ENV_VARS`**\n```bash\nSHAKAPACKER_ENV_VARS=API_URL,FEATURE_FLAG bundle exec rails assets:precompile\n```\n\n### Action Required\n\nAfter upgrading, **rotate any secrets** that may have been exposed in previously compiled JavaScript bundles.\n\n### Resources\n\n- Fix PR: https://github.com/shakacode/shakapacker/pull/857","modified":"2026-02-03T03:15:57.934161Z","published":"2026-01-08T21:13:37Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-200"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-01-08T21:13:37Z"},"references":[{"type":"WEB","url":"https://github.com/shakacode/shakapacker/security/advisories/GHSA-96qw-h329-v5rg"},{"type":"WEB","url":"https://github.com/shakacode/shakapacker/pull/857"},{"type":"WEB","url":"https://github.com/shakacode/shakapacker/commit/3e06781b18383c5c2857ed3a722f7b91bdc1bc0e"},{"type":"PACKAGE","url":"https://github.com/shakacode/shakapacker"}],"affected":[{"package":{"name":"shakapacker","ecosystem":"npm","purl":"pkg:npm/shakapacker"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"9.5.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-96qw-h329-v5rg/GHSA-96qw-h329-v5rg.json"}},{"package":{"name":"shakapacker","ecosystem":"RubyGems","purl":"pkg:gem/shakapacker"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"9.5.0"}]}],"versions":["6.0.0","6.0.0.rc.12","6.0.0.rc.13","6.0.0.rc.14","6.0.0.rc.6","6.0.1","6.0.2","6.1.0","6.1.0.beta.0","6.1.1","6.2.0","6.2.1","6.3.0","6.3.0.pre.rc.1","6.4.0","6.4.1","6.5.0","6.5.1","6.5.2","6.5.3","6.5.4","6.5.5","6.5.6","6.6.0","7.0.0","7.0.0.rc.0","7.0.0.rc.1","7.0.0.rc.2","7.0.1","7.0.2","7.0.3","7.1.0","7.2.0","7.2.0.rc.0","7.2.1","7.2.2","7.2.3","7.3.0.beta.1","8.0.0","8.0.0.pre.rc.1","8.0.0.rc.2","8.0.0.rc.3","8.0.0.rc.4","8.0.1","8.0.2","8.1.0","8.2.0","8.3.0","8.4.0","9.0.0","9.0.0.beta.0","9.0.0.beta.10","9.0.0.beta.11","9.0.0.beta.2","9.0.0.beta.3","9.0.0.beta.4","9.0.0.beta.5","9.0.0.beta.6","9.0.0.beta.7","9.0.0.beta.8","9.0.0.beta.9","9.1.0","9.2.0","9.3.0","9.3.0.beta.0","9.3.0.beta.1","9.3.0.beta.2","9.3.0.beta.4","9.3.0.beta.5","9.3.0.beta.6","9.3.0.beta.7","9.3.1","9.3.2","9.3.3","9.3.4","9.3.4.beta.0","9.4.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-96qw-h329-v5rg/GHSA-96qw-h329-v5rg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}