Security research PoC - Wix SSR manifest injection test
The Wix manifest loads bundles that contact a fixed external webhook. The model gathers host and runtime data, probes localhost services, and sends results to that receiver.
Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/poc-model.bundle.min.jsView on unpkg · L2Source appears to send environment or credential material to an external endpoint.
dist/poc-model.bundle.min.jsView on unpkg · L2Source collects local host identity data and sends it to an external endpoint.
dist/poc-model.bundle.min.jsView on unpkg · L2The referenced model bundle collects runtime and host details, including environment data and network interfaces.
dist/poc-model.bundle.min.jsView on unpkg · L12The model bundle sends collected results to a fixed webhook.site endpoint.
dist/poc-model.bundle.min.jsView on unpkg · L24This report applies to wix-ssr-thunderbolt-grid-polyfill@0.1.0.
See version security history for other recorded verdicts.
Evidence last updated: .
Source advisory published: .
The referenced model bundle collects runtime and host details, including environment data and network interfaces.
dist/poc-model.bundle.min.jsView on unpkg · L12The model bundle sends collected results to a fixed webhook.site endpoint.
dist/poc-model.bundle.min.jsView on unpkg · L24Source sends credentials or rich application records to a package-controlled external receiver enabled by default.
dist/poc-model.bundle.min.jsView on unpkg · L2Source appears to send environment or credential material to an external endpoint.
dist/poc-model.bundle.min.jsView on unpkg · L2Source collects local host identity data and sends it to an external endpoint.
dist/poc-model.bundle.min.jsView on unpkg · L2