Executive brief
DOMPurify is a popular HTML sanitization library used to protect web applications from script injection attacks. A demonstration page in the library lacks proper link security attributes, allowing attackers to perform reverse tabnabbing—hijacking the browser tab that opened a link to redirect users or steal information. This could be exploited if users interact with the vulnerable demo page.
Technical details
The vulnerability is a reverse tabnabbing issue (CWE-601) in the hooks-target-blank-demo.html demonstration file of DOMPurify versions before 1.0.11. When links open in a new tab (target="_blank"), they lack the rel="noopener noreferrer" attribute, allowing the opened page to access and manipulate the opener window via the window.opener object. An attacker controlling a link target can redirect the original tab or extract sensitive data. The fix, merged in PR #337, adds the missing security attributes to prevent this attack. The vulnerability requires user interaction (clicking a link) but has network-level impact due to cross-site window access.
Affected products
- Cure53 DOMPurify before 1.0.11
Timeline
- 2023-11-14: disclosed: GHSA published
- 2023-11-07: advisory: CVE-2019-25155 published on NVD
- 2019-05-15: patched: PR #337 merged fixing reverse tabnabbing in demo