Junglewise Threat Intelligence

CVE-2019-0542: xterm.js remote code execution via special character handling

CVE-2019-0542 · Severity: low · CVSS 3.1 · Published 2019-01-14

Executive brief

xterm.js is a popular JavaScript terminal emulator library used in web applications. The vulnerability allows remote code execution when the library mishandles special characters in terminal input, potentially allowing attackers to execute arbitrary code on systems running vulnerable versions. User interaction is required to trigger the vulnerability.

Technical details

The vulnerability exists in xterm.js due to improper handling of special characters (CWE-94: Improper Control of Generation of Code, 'Code Injection'). The root cause involves the request term info handler in InputHandler.ts, which was removed in the fix. The attack vector requires network access and user interaction—the user must interact with a vulnerable terminal instance containing specially crafted input. An attacker can achieve remote code execution by injecting malicious input through terminal sequences. The vulnerability affects multiple version ranges: all versions before 3.8.1, versions 3.9.0 to 3.9.1, and versions 3.10.0. Patches are available in 3.8.1, 3.9.2, and 3.10.1 or later.

Affected products

  • xtermjs xterm.js before 3.8.1, 3.9.0 to 3.9.1, 3.10.0

Timeline

  • 2019-01-14: disclosed
  • 2019-01-09: patched: Fix available in 3.8.1, 3.9.2, 3.10.1

References