Potential vulnerability: exposure of sensitive secret in SolidStart frontend bundle #3894

Open
opened 2026-02-16 17:41:51 -05:00 by yindo · 0 comments
Owner

Originally created by @Mehrad25Software on GitHub (Dec 26, 2025).

Originally assigned to: @thdxr on GitHub.

Description

While reviewing the SST, Cloudflare and SolidStart setup, I noticed that several sensitive secrets are linked directly to the SolidStart “Console” app. Depending on how SST injects linked resources and how SolidStart/Vite handles env exposure, there may be a risk of unintentionally exposing server-only secrets to the frontend bundle.

This may already be handled safely by SST, but the current configuration makes it non obvious and could be a footgun for future contributors.

OpenCode version

No response

Steps to reproduce

No response

Screenshot and/or share link

No response

Operating System

No response

Terminal

No response

Originally created by @Mehrad25Software on GitHub (Dec 26, 2025). Originally assigned to: @thdxr on GitHub. ### Description While reviewing the SST, Cloudflare and SolidStart setup, I noticed that several sensitive secrets are linked directly to the SolidStart “Console” app. Depending on how SST injects linked resources and how SolidStart/Vite handles env exposure, there may be a risk of unintentionally exposing server-only secrets to the frontend bundle. This may already be handled safely by SST, but the current configuration makes it non obvious and could be a footgun for future contributors. ### OpenCode version _No response_ ### Steps to reproduce _No response_ ### Screenshot and/or share link _No response_ ### Operating System _No response_ ### Terminal _No response_
yindo added the bug label 2026-02-16 17:41:51 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: anomalyco/opencode#3894