Uh oh!
There was an error while loading. Please reload this page.
') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ', 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); })();
There was an error while loading. Please reload this page.
Summary
DupFileManager's generated report and its advanced options page both load JavaScript from
https://www.axter.com/js/, and both pages hold the user's Stash API key. Third-party script therefore executes in a page that has full API access to the user's Stash instance.This is a design/supply-chain issue rather than an active exploit — nothing is known to be wrong with the domain today. The point is that the security of every DupFileManager user's Stash instance currently depends on a single third-party domain staying under its owner's control indefinitely.
The two facts that combine
1. The pages load remote script with no integrity pinning
DupFileManager_report_config.py:187-189(the generated duplicate report):advance_options.html:93-95loads the same three.No
integrity/ SRI attribute, so a changed file at that URL is executed without complaint.2. Those same pages hold the API key
DupFileManager_report_config.py:191declaresvar apiKey = "", and line 225 attaches it to every request to Stash:Line 349 then passes it to the options page in the URL query string:
and
advance_options.html:100-101reads it back out oflocation.search.Impact
Any party able to serve content at
www.axter.com/js/— through domain expiry and re-registration, DNS or hosting compromise, or an MITM on a user who reaches the page over plain HTTP — gets arbitrary JavaScript execution in a page holding a valid Stash API key. From there: read the entire library, and drive any mutation the API allows, including scene and file deletion.For users who expose Stash beyond their LAN, that is reachable remotely.
Two smaller issues in the same area:
Refererheaders on any outbound request from that page — including the requests toaxter.com. Worth moving out of the URL regardless of the rest.advance_options.html:126doesconsole.log("Using apiKey = " + apiKey), writing the key to the browser console.Suggested fixes
In rough order of value:
sessionStorage, or apostMessagefrom the opener, keeps it out of history andReferer.console.logof the key.crossoriginis a meaningful improvement on an unpinned personal domain — though vendoring is still better for a self-hosted, often-offline application.Notes
axter.comreferences in FileMonitor and RenameFile are author-attribution comments in headers, not resource loads.SECURITY.mdand private vulnerability reporting is not enabled. Happy to move this somewhere private if maintainers would prefer.