Only the latest release on npm gets security fixes. Upgrade with npm install -g front-proxy@latest before reporting.
Please don't open a public issue. Report it privately through GitHub: open a security advisory.
Include:
- the front-proxy version (
npm ls -g front-proxy), Node version and OS - what an attacker can do, and what they need to have or control first
- steps or a proof of concept to reproduce it
You'll get a reply within 7 days. Once a fix is released, the advisory is published with credit to you, unless you'd rather stay anonymous.
front-proxy start runs as root, so these matter most:
/etc/hostsedits: anything that could write lines other than the front-proxy block- the config and certs in
~/.front-proxy(or$FRONT_PROXY_HOME): file paths, ownership and permissions - the admin page on
front-proxy.localhost: requests from other sites or non-loopback clients that get through its checks - the reverse proxy on ports 80 and 443: routing a request somewhere other than the mapped
127.0.0.1port
npm packages are published from GitHub Actions with trusted publishing, so they carry npm provenance:
npm audit signaturesEach GitHub release also has the published tarball and its Sigstore bundle (.sigstore.json). To check a downloaded tarball:
gh attestation verify front-proxy-X.Y.Z.tgz --repo gutomezencio/front-proxy