Skip to content

Critical protobufjs RCE vulnerability reachable via onnxruntime-web/@ricky0123/vad-web (shipped in the extension bundle) #650

Description

@rosscado

Problem: npm audit --omit=dev (2026-09-07, weekly maintenance routine) reports a critical severity finding — "Arbitrary code execution in protobufjs" plus several other protobufjs advisories (prototype pollution / code-injection gadgets in generated message constructors, DoS via unbounded recursion) — reachable through onnx-proto → onnxruntime-web → @ricky0123/vad-web, a direct production dependency (package.json dependencies).

Scope: @ricky0123/vad-web (pinned ^0.0.24, installed 0.0.24) and onnxruntime-web (pinned exact 1.14.0) are imported directly in the shipped extension bundle — confirmed usage in src/vad/OnscreenVADClient.ts, src/vad/VADConfigs.ts, src/offscreen/vad_handler.ts, and src/offscreen/synthetic-audio.ts (the offscreen-document VAD pipeline described in src/vad/README.md). This is genuine shipped-product exposure, not dev-only tooling. Out of scope: the other npm audit findings rooted in Node-side dev tooling only (express/http-proxy-middleware/serve-handler, used by server.js / npm start, not bundled into the extension) — lower priority, not filed here.

Reproduction / verification:

  1. npm ci && npm audit --omit=dev --json
  2. Observe protobufjs at severity: "critical" with fixAvailable: {"name":"@ricky0123/vad-web","version":"0.0.30","isSemVerMajor":true} — the only available fix is a @ricky0123/vad-web bump (0.0.24 → 0.0.30), which pulls a newer onnxruntime-web/onnx-proto/protobufjs.
  3. Also present in the same chain: onnx-proto (high) and onnxruntime-web (high), both fixed only by the same bump.

Expected: no critical/high vulnerabilities in the dependency chain that ships inside the browser-extension bundle. Actual: 1 critical + 2 high findings, all rooted in protobufjs, all requiring the same @ricky0123/vad-web major-boundary bump to resolve.

Acceptance criteria:

  • @ricky0123/vad-web (and its transitive onnxruntime-web/onnx-proto/protobufjs) upgraded past the vulnerable versions, verified by a clean npm audit --omit=dev for this chain.
  • Full VAD regression coverage passes post-bump: npm test, the VAD unit/contract tests, and the VAD benchmark (npm run bench:vad) — per src/vad/README.md's note that all 4 copied WASM files are load-bearing, confirm npm run copy-onnx still produces the expected WASM set against the new onnxruntime-web version (file names/count can change across versions).
  • A real-host or Layer-3/4 smoke pass confirms the offscreen VAD pipeline (src/offscreen/vad_handler.ts) still detects speech correctly after the bump, since this is exactly the kind of "looks-mechanical-is-a-trap" dependency swap doc/codebase-caution-map.md warns about.

Notes/Hypotheses (non-binding): fixAvailable.isSemVerMajor: true is likely an artifact of @ricky0123/vad-web being pre-1.0 (npm treats any 0.0.x → 0.0.y bump as a major-equivalent boundary) rather than evidence of an actual breaking API change — worth checking the vad-web changelog/diff between 0.0.24 and 0.0.30 before assuming a large migration. Per AGENTS.md, this routine does not bump dependencies itself; filing for a human/agent session to pick up via the normal fail-first-TDD + isolated-worktree flow.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions