Junglewise Threat Intelligence

CVE-2019-17625: Rambox stored XSS and remote code execution in service name field

CVE-2019-17625 · Severity: low · CVSS 3.1 · Published 2022-05-24

Vendors: npm.

Executive brief

Rambox is a workspace browser that combines various messaging and emailing applications into a single interface. A security vulnerability in version 0.6.9 allows an attacker to execute malicious code on a user's computer if they can convince the user to add or edit a service with a specially crafted name. This could lead to a full system compromise, allowing unauthorized access to personal data and sensitive communications.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Rambox 0.6.9 due to improper sanitization of the 'name' field when adding or editing a service. Because Rambox is built on Electron and Node.js, an attacker can leverage this XSS to escape the web context and execute arbitrary system commands. By crafting a payload within an HTML attribute (such as 'onerror' in an IMG tag) that utilizes Node.js 'child_process.exec', an attacker can achieve full remote code execution (RCE) on the host operating system. Exploitation requires the victim to interact with the malicious service entry.

Affected products

  • Rambox Rambox 0.6.9 and earlier

Timeline

  • 2019-10-16: disclosed: Vulnerability reported on GitHub and CVE assigned
  • 2019-10-16: advisory: NVD published CVE-2019-17625
  • 2022-05-24: advisory: GitHub Advisory GHSA-2gc6-2h2g-ph48 published

References