Executive brief
The public npm package, used for serving static files and directories in Node.js applications, contains a Cross-Site Scripting (XSS) vulnerability in versions prior to 0.1.4. An attacker can craft files with malicious JavaScript code in their filenames, which are then executed in users' browsers when those files are accessed. This could allow attackers to steal session cookies, redirect users to malicious sites, or perform other unauthorized actions on behalf of the victim.
Technical details
The vulnerability is a reflected Cross-Site Scripting (XSS) flaw caused by insufficient sanitization of filename input in the public package. When serving static files, the application fails to properly escape or sanitize filenames before including them in HTML responses. An attacker can create files with names containing HTML/JavaScript payloads (e.g., "<img src=x onerror=alert('xss')>.txt"). When a victim visits a URL serving such a file, the malicious code in the filename executes in their browser context. The attack requires user interaction (clicking a malicious link), but does not require authentication. The fix was implemented in version 0.1.4 and later.
Affected products
- npm public prior to 0.1.4
Timeline
- 2018-10-10: disclosed