Executive brief
The validator library for Node.js, which is used by developers to sanitize and verify user input, contains a flaw in its cross-site scripting (XSS) filter. An attacker can bypass this security protection by using specially crafted 'javascript:' links. If successful, this could allow an attacker to execute malicious scripts in a user's browser, potentially leading to unauthorized actions or the theft of sensitive session information.
Technical details
A vulnerability exists in the validator library for Node.js (versions prior to 1.1.0) where the XSS filtering logic fails to properly sanitize 'javascript:' URIs. By crafting a specific URI, a remote attacker can bypass the filter to inject and execute arbitrary JavaScript in the context of the victim's browser session. This is a classic XSS filter bypass that occurs during input validation or sanitization. The issue is resolved in version 1.1.0 and later. Exploitation typically requires a user to interact with a malicious link or for the application to render the unsanitized input.
Affected products
- Node.js validator < 1.1.0
Timeline
- 2013-12-12: disclosed: Original vulnerability discovery date (based on CVE year)
- 2016-04-20: advisory: Public disclosure on oss-security mailing list
- 2017-01-23: advisory: NVD publication date