Executive brief
bleach is a popular open-source library used to sanitize and clean HTML content, preventing malicious scripts from being embedded in web applications. A vulnerability in bleach's sanitization logic allows attackers to bypass the HTML filtering with specially crafted payloads, enabling them to inject and execute arbitrary JavaScript in users' browsers—potentially leading to session hijacking, credential theft, or malware distribution.
Technical details
This is a cross-site scripting (CWE-79) vulnerability in bleach's HTML sanitization filter. The vulnerability allows attackers to bypass the package's sanitization mechanism using polyglot payloads such as "<<script><<\/script>script>alert('xss');<\/<<\/script><<\/script>script>" that confuse the parser into misinterpreting tag boundaries. The attack is network-based and requires no authentication or user interaction beyond the victim viewing content sanitized with the vulnerable bleach version. A successful exploit allows arbitrary JavaScript execution in the victim's browser context. At the time of disclosure, no patch was available, and the advisory recommended switching to alternative HTML sanitization libraries.
Affected products
- bleach contributors bleach
Timeline
- 2020-09-03: disclosed: Vulnerability disclosed via GitHub Security Advisory GHSA-5634-rv46-48jf
- 2020-08-31: advisory: Advisory reviewed and added to GitHub advisory database