Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2023-38704: import-in-the-middle can run attacker code via unsafe imports

CVE-2023-38704 · published 3 years ago
Summary

The JavaScript helper called import-in-the-middle, used in some build and monitoring tools, can let an attacker execute their own code if a program feeds it directly into the dynamic import function. This happens when the program trusts user‑supplied text to decide which code to load. Fix the problem by updating the helper to version 1.4.2 or newer, and make sure any user input is checked against an approved list before being used for dynamic imports; if you do not need this feature, disable it in your command‑line or system settings.

What to do
  • Update GitHub Actions import-in-the-middle to version 1.4.2.
  • Update import-in-the-middle to version 1.3.4-aikido.1.
  • Update rootio @rootio/import-in-the-middle to version 1.3.4-root.io.1.
  • Update datadoghq import-in-the-middle to version 1.4.2 or later.
Affected software
Ecosystem VendorProductAffected versions
npm GitHub Actions import-in-the-middle <= 1.4.1
Fix: upgrade to 1.4.2
– datadoghq import-in-the-middle < 1.4.2
cpe:2.3:a:datadoghq:import-in-the-middle:*:*:*:*:*:node.js:*:*
Root:npm – import-in-the-middle < 1.3.4-aikido.1
Fix: upgrade to 1.3.4-aikido.1
Root:npm rootio @rootio/import-in-the-middle < 1.3.4-root.io.1
Fix: upgrade to 1.3.4-root.io.1
Original advisory text
CVE-2023-38704 in import-in-the-middle - Patched by Root
import-in-the-middle is a module loading interceptor specifically for ESM modules. The import-in-the-middle loader works by generating a wrapper module on the fly. The wrapper uses the module specifier to load the original module and add some wrapping code. Prior to version 1.4.2, it allows for remote code execution in cases where an application passes user-supplied input directly to the `import()` function. This vulnerability has been patched in import-in-the-middle version 1.4.2.

Some workarounds are available. Do not pass any user-supplied input to `import()`. Instead, verify it against a set of allowed values. If using import-in-the-middle, directly or indirectly, and support for EcmaScript Modules is not needed, ensure that no options are set, either via command-line or the `NODE_OPTIONS` environment variable, that would enable loader hooks.
Fix within
Internet-facing 60 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker partial control
Severity
9.8 Critical
Exploitation
1% chance of attack within 30 days
Type
CWE-20Improper Input Validation
Timeline
Published7 Aug 2023
Updated7 Oct 2026
First seen6 Mar 2026
Track software like this
Free during beta