Executive brief
dwebp-bin is a Node.js wrapper for the WebP image decoder tool. The package downloads a required executable over unencrypted HTTP during installation, making it vulnerable to interception attacks. A network attacker can replace the download with malicious code, leading to complete compromise of any system running the package. No fix has been released.
Technical details
dwebp-bin is vulnerable to a man-in-the-middle (MITM) attack due to insecure download of the dwebp executable over HTTP instead of HTTPS. The vulnerability exists in the installation/initialization logic and affects all versions up to and including 1.0.0. Attack vector is network-based but requires the attacker to have a privileged network position (e.g., rogue ISP, compromised router, public Wi-Fi) to intercept the HTTP response. Since the downloaded resource is an executable that is subsequently executed, successful exploitation results in arbitrary code execution with the privileges of the user running the package. No patch has been released by the maintainers; mitigation requires avoiding the package entirely or restricting its use to isolated private networks only.
Affected products
- npm dwebp-bin <= 1.0.0
Timeline
- 2019-02-18: disclosed
- 2016: other: CVE-2016-10633 assigned for this vulnerability