Executive brief
@nuxt/devalue is a JavaScript library used to serialize complex data structures for transfer between server and client in web applications. A cross-site scripting (XSS) vulnerability in versions prior to 1.2.3 allows attackers to inject malicious JavaScript code through specially crafted object keys, potentially compromising user sessions, stealing data, or defacing web pages.
Technical details
The vulnerability is a classic cross-site scripting (CWE-79) flaw caused by insufficient input sanitization when handling object keys during serialization. Attackers can inject arbitrary JavaScript code by embedding malicious characters in object property names, which are then unsanitized in the serialized output. The attack requires network access and user interaction (the victim must load a page containing the malicious serialized data), but does not require authentication. An attacker can execute arbitrary JavaScript in the context of the vulnerable application's domain. The fix was released in version 1.2.3; users should upgrade immediately.
Affected products
- Nuxt devalue prior to 1.2.3
Timeline
- 2019-04-12: disclosed: Issue reported on GitHub
- 2019-07-15: patched: Fix released in version 1.2.3
- 2019-07-16: advisory