A plugin for faststore with buyer portal
Authenticated buyer-portal pages disclose VTEX tokens and associated session or identity data to hard-coded external Vercel-hosted iframe applications. This occurs during normal page rendering.
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
src/features/b2b-agent/layouts/B2BAgentLayout/B2BAgentLayout.tsxView on unpkgA second buyer-operations page sends the same authentication token and account/user data to another hard-coded Vercel agent.
src/features/b2b-agent/layouts/B2BAgentLayout/B2BAgentLayout.tsxView on unpkg · L6The order-entry page extracts a VTEX authentication token from client cookie data.
src/pages/order-entry.tsxView on unpkg · L90On rendering, the package embeds a hard-coded external Vercel agent and posts the token, session, segment, account, locale, and user identifiers to it.
src/features/order-entry/layouts/OrderEntryLayout.tsxView on unpkg · L10On rendering, the package embeds a hard-coded external Vercel agent and posts the token, session, segment, account, locale, and user identifiers to it.
src/features/order-entry/layouts/OrderEntryLayout.tsxView on unpkg · L63This report applies to @vtex/faststore-plugin-buyer-portal@2.0.28.
See version security history for other recorded verdicts.
Evidence last updated: .
A second buyer-operations page sends the same authentication token and account/user data to another hard-coded Vercel agent.
src/features/b2b-agent/layouts/B2BAgentLayout/B2BAgentLayout.tsxView on unpkg · L6Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
src/features/b2b-agent/layouts/B2BAgentLayout/B2BAgentLayout.tsxView on unpkgThe order-entry page extracts a VTEX authentication token from client cookie data.
src/pages/order-entry.tsxView on unpkg · L90On rendering, the package embeds a hard-coded external Vercel agent and posts the token, session, segment, account, locale, and user identifiers to it.
src/features/order-entry/layouts/OrderEntryLayout.tsxView on unpkg · L10On rendering, the package embeds a hard-coded external Vercel agent and posts the token, session, segment, account, locale, and user identifiers to it.
src/features/order-entry/layouts/OrderEntryLayout.tsxView on unpkg · L63