Executive brief
Remarkable is a popular library used to convert Markdown text into HTML for display on websites. A security flaw in the way it handles web links allows an attacker to hide malicious scripts inside a link using invisible characters. If a user clicks on one of these specially crafted links, the attacker could steal their login information or perform actions on their behalf.
Technical details
A Cross-site Scripting (XSS) vulnerability exists in Remarkable versions prior to 1.7.2. The issue resides in 'lib/parser_inline.js' (and specifically 'parse_link_destination.js'), where the URL filtering logic failed to account for unprintable ASCII control characters. An attacker can bypass the 'javascript:' protocol filter by prefixing the URI with a control character (e.g., '\x0e'). When rendered and clicked in a browser, the control character is ignored or handled in a way that allows the JavaScript to execute. This is a network-reachable vulnerability requiring user interaction (clicking the link) to achieve execution in the context of the victim's session. The fix, introduced in version 1.7.2, updates the parser to disallow all ASCII control characters (code < 0x20 or 0x7F) in link destinations.
Affected products
- jonschlinkert remarkable < 1.7.2
Timeline
- 2019-05-13: disclosed: Issue reported on GitHub
- 2019-05-13: patched: Fix committed to repository
- 2019-05-29: advisory: GitHub Advisory published