Junglewise Threat Intelligence

CVE-2019-5422: buttle Cross-Site Scripting in filename sanitization

CVE-2019-5422 · Severity: info · CVSS 0 · Published 2019-04-08

Technologies: buttle (npm). Vendors: npm.

Executive brief

buttle is a Node.js package used for file processing and display. The package fails to sanitize filenames, allowing attackers to inject malicious JavaScript code that executes in users' browsers when files with crafted names are processed. This can lead to account compromise, credential theft, or malware distribution.

Technical details

This is a Cross-Site Scripting (CWE-79) vulnerability in the buttle npm package affecting all versions through 0.2.0. The root cause is improper sanitization of filenames—user-supplied or attacker-controlled filenames containing JavaScript payloads are rendered without escaping, allowing arbitrary script execution in the victim's browser. The attack vector is network-based and requires the attacker to create or upload a file with a malicious name; the victim must view or process that file for the XSS to execute. No patch is currently available according to the advisory.

Affected products

  • npm buttle 0.2.0 and earlier

Timeline

  • 2019-04-08: disclosed: GHSA-gm29-35c7-8cfw published

References

Related threats