Executive brief
jsoneditor is a popular JavaScript library used to view and edit JSON data in web applications. A stored cross-site scripting (XSS) vulnerability in the tree mode allows attackers to inject malicious JavaScript code that persists and executes when users view the edited JSON, potentially compromising user sessions or stealing sensitive data.
Technical details
The vulnerability is a stored XSS (CWE-79) in jsoneditor's tree mode that occurs through improper input sanitization when processing JSON data. An attacker can inject arbitrary JavaScript code into JSON values, which is then executed in the browser when the tree is rendered. The attack requires no authentication but does require user interaction (clicking the tree display or input elements). The vulnerable versions are all releases before 9.0.2; the fix is available in version 9.0.2 and later.
Affected products
- Jos de Jong jsoneditor before 9.0.2
Timeline
- 2020-07-01: disclosed
- 2021-10-12: patched: Fix released in version 9.0.2