Executive brief
The mustache library, a popular tool for generating web pages from templates, contains a security flaw in how it handles certain data. An attacker can use this flaw to inject malicious scripts into a website, potentially leading to the theft of user session information or unauthorized actions on behalf of visitors. This issue is particularly relevant for applications that use mustache templates with unquoted HTML attributes.
Technical details
A cross-site scripting (XSS) vulnerability exists in the mustache.js library due to improper neutralization of input during web page generation. Specifically, the template engine fails to correctly escape data when it is used within unquoted HTML attributes. A remote attacker can provide a crafted template or malicious data that leverages this lack of quoting to inject and execute arbitrary JavaScript in the context of the user's browser session. This vulnerability was addressed in version 2.2.1.
Affected products
- mustache.js project mustache.js before 2.2.1
Timeline
- 2015-12-31: disclosed: CVE assigned in 2015
- 2016-04-20: advisory: Public disclosure via oss-security mailing list
- 2017-01-23: advisory: NVD publication date