Executive brief
gmail-js is a JavaScript library that provides programmatic access to Gmail. The library is vulnerable to DOM-based cross-site scripting (XSS) because it dynamically constructs and executes JavaScript code from API response data without proper sanitization. An attacker who can control or intercept API responses could inject malicious code that executes in the context of a user's browser session, potentially stealing credentials, intercepting emails, or performing actions on behalf of the user.
Technical details
The vulnerability is a DOM-based XSS (CWE-79) in multiple functions (tools.parse_response, helper.get.visible_emails_post, and helper.get.email_data_post) that pass unsanitized user/server input directly into the Function constructor. The root cause is the use of `new Function('return ' + data)` to dynamically execute code derived from Gmail API responses. An attacker who can control API response data (via man-in-the-middle, malicious proxy, or compromised server response) can inject arbitrary JavaScript. No authentication bypass or special privileges are required beyond ability to influence the API response. The vulnerability affects all versions prior to 0.6.5, which provides a fix.
Affected products
- <UNKNOWN> gmail-js < 0.6.5
Timeline
- 2016-07-12: disclosed
- 2016: patched: Fix released in version 0.6.5
- 2020-09-01: advisory