Executive brief
fileview is an npm package for displaying file listings in web applications. The package fails to sanitize filenames, allowing attackers to inject malicious JavaScript code through specially crafted file names. When a victim views files in the application, the injected script executes in their browser, potentially compromising their session, stealing credentials, or performing unauthorized actions on their behalf.
Technical details
The vulnerability is a Cross-Site Scripting (CWE-79) flaw affecting all versions of fileview. The package does not properly sanitize or escape filenames before rendering them in the browser, allowing an attacker to inject arbitrary JavaScript through files with malicious names. The attack vector is network-based and requires the victim to visit a page displaying files with crafted names; no authentication or special privileges are required. An attacker can execute arbitrary JavaScript in the victim's browser context. No patch was available at the time of advisory publication (2020-04-01); the recommendation is to use an alternative package.
Affected products
- itworkcenter fileview 0.1.6 and all earlier versions
Timeline
- 2019-07-09: disclosed: Security issue reported to GitHub
- 2020-04-01: advisory: GHSA published
- 2020-04-01: other: No fix available; alternative package recommended