Junglewise Threat Intelligence

CVE-2019-25155: DOMPurify reverse tabnabbing in demo page

CVE-2019-25155 · Severity: low · CVSS 3.1 · Published 2023-11-14

Technologies: dompurify (npm). Vendors: npm.

Executive brief

DOMPurify is a popular HTML sanitization library used to protect web applications from script injection attacks. A demonstration page in the library lacks proper link security attributes, allowing attackers to perform reverse tabnabbing—hijacking the browser tab that opened a link to redirect users or steal information. This could be exploited if users interact with the vulnerable demo page.

Technical details

The vulnerability is a reverse tabnabbing issue (CWE-601) in the hooks-target-blank-demo.html demonstration file of DOMPurify versions before 1.0.11. When links open in a new tab (target="_blank"), they lack the rel="noopener noreferrer" attribute, allowing the opened page to access and manipulate the opener window via the window.opener object. An attacker controlling a link target can redirect the original tab or extract sensitive data. The fix, merged in PR #337, adds the missing security attributes to prevent this attack. The vulnerability requires user interaction (clicking a link) but has network-level impact due to cross-site window access.

Affected products

  • Cure53 DOMPurify before 1.0.11

Timeline

  • 2023-11-14: disclosed: GHSA published
  • 2023-11-07: advisory: CVE-2019-25155 published on NVD
  • 2019-05-15: patched: PR #337 merged fixing reverse tabnabbing in demo

References

Related threats