Executive brief
@risingstack/protect is a Node.js security library designed to help developers prevent common web vulnerabilities. The library's XSS validator function (isXss()) contains multiple bypasses that allow attackers to inject and execute arbitrary JavaScript code in users' browsers, potentially enabling credential theft, session hijacking, or malware distribution.
Technical details
The vulnerability is a Cross-Site Scripting (XSS) flaw in the isXss() validation function (CWE-79). The validator has multiple bypass techniques that fail to properly sanitize or detect XSS payloads, allowing malicious JavaScript to pass validation checks. An attacker can craft specially-formed payloads to evade the filter and inject executable code. The vulnerability is network-reachable via any application using this library to validate untrusted input. No patch is available; the package is unmaintained and the vendor recommends using alternative security libraries.
Affected products
- RisingStack protect up to 1.2.0
Timeline
- 2018-04-25: disclosed