Junglewise Threat Intelligence

CVE-2019-13506: Nuxt devalue cross-site scripting in object keys

CVE-2019-13506 · Severity: low · CVSS 3 · Published 2019-07-16

Vendors: Nuxt, npm.

Executive brief

@nuxt/devalue is a JavaScript library used to serialize complex data structures for transfer between server and client in web applications. A cross-site scripting (XSS) vulnerability in versions prior to 1.2.3 allows attackers to inject malicious JavaScript code through specially crafted object keys, potentially compromising user sessions, stealing data, or defacing web pages.

Technical details

The vulnerability is a classic cross-site scripting (CWE-79) flaw caused by insufficient input sanitization when handling object keys during serialization. Attackers can inject arbitrary JavaScript code by embedding malicious characters in object property names, which are then unsanitized in the serialized output. The attack requires network access and user interaction (the victim must load a page containing the malicious serialized data), but does not require authentication. An attacker can execute arbitrary JavaScript in the context of the vulnerable application's domain. The fix was released in version 1.2.3; users should upgrade immediately.

Affected products

  • Nuxt devalue prior to 1.2.3

Timeline

  • 2019-04-12: disclosed: Issue reported on GitHub
  • 2019-07-15: patched: Fix released in version 1.2.3
  • 2019-07-16: advisory

References