Executive brief
Nunjucks is a templating engine commonly used in web applications to render dynamic content. A flaw in the auto-escape protection allows attackers to inject malicious scripts by passing specially crafted array-based input, bypassing the security filter meant to prevent cross-site scripting attacks. This could enable account theft, credential theft, or malware distribution.
Technical details
The vulnerability is a cross-site scripting (CWE-79) flaw in Nunjucks' auto-escape mode. When template variables are passed as arrays rather than strings, the escape filter is not applied, allowing script injection. The attack requires no authentication and is triggered via network input (e.g., query parameters in a web framework). An attacker can craft a request like ?name[]=<script>alert(1)</script> which bypasses escaping in template rendering. The vulnerability was fixed in Nunjucks version 2.4.3 and later.
Affected products
- Mozilla Nunjucks before 2.4.3
Timeline
- 2016-09-07: disclosed: Issue #835 opened on GitHub
- 2016: patched: Fixed in version 2.4.3
- 2018-11-06: advisory: GHSA-f7ph-p5rv-phw2 published