Executive brief
bracket-template is a JavaScript templating library that processes variables in template strings. The library is vulnerable to stored cross-site scripting (XSS) when variables received from URL parameters (GET requests) are used directly in templates without sanitization. An attacker can inject malicious JavaScript code that executes in users' browsers, potentially stealing session cookies, credentials, or redirecting users to malicious sites.
Technical details
bracket-template contains a stored cross-site scripting (CWE-79) vulnerability affecting all versions through 1.1.5. The root cause is insufficient input validation and output encoding when template variables, particularly those sourced from GET request parameters, are processed. The vulnerability is triggered when user-controlled data passed via query parameters is directly interpolated into templates without HTML entity encoding or content security measures. An attacker can craft a malicious URL containing JavaScript payloads that persist in the rendered template output. No patch has been released; the advisory recommends discontinuing use of the module.
Affected products
- bracket-template bracket-template all versions through 1.1.5
Timeline
- 2019-05-30: disclosed