Junglewise Threat Intelligence

CVE-2017-16006: remarkable XSS via data URI in links

CVE-2017-16006 · Severity: info · Published 2018-11-09

Technologies: Remarkable. Vendors: npm.

Executive brief

Remarkable is a JavaScript markdown parser widely used in web applications to convert markdown text into HTML. The library failed to block data: URIs in markdown links, allowing attackers to craft markdown containing malicious JavaScript that would execute in the browser of anyone viewing the rendered content. This could lead to session hijacking, credential theft, or malware delivery.

Technical details

The vulnerability is a cross-site scripting (XSS) flaw in remarkable's link validation logic (CWE-79). The markdown parser did not filter or block data: URIs in link targets, allowing attackers to embed data: URLs containing JavaScript payloads (e.g., `[link](data:text/html,<script>alert('xss')</script>)`). When a user clicks such a link or the page is rendered, the JavaScript executes in the security context of the hosting domain. The vulnerability affects all versions prior to 1.7.0, and requires only that an attacker can inject markdown content into a document processed by the library. A fix was released in v1.7.0 with proper URI scheme validation.

Affected products

  • remarkable remarkable <1.7.0

Timeline

  • 2016-08-20: disclosed: Issue reported on GitHub
  • 2018-11-09: advisory: GHSA advisory published
  • 2017-01-01: patched: Fix released in v1.7.0

References

Related threats