Executive brief
highlight.js is a popular syntax highlighting library used to display code on web pages. A malicious code block crafted with a specially-formatted language name can pollute the base object's prototype, causing unexpected behavior, application crashes, or denial of service in web applications that allow users to insert custom HTML code blocks without filtering language names.
Technical details
The vulnerability is a prototype pollution flaw (CWE-471) in the language and alias parsing logic of highlight.js versions prior to 9.18.2 and 10.0.0–10.1.1. When processing user-supplied HTML code blocks (commonly from Markdown), an attacker can craft a malicious language name that pollutes the JavaScript base object prototype during highlighting. This requires network access and user interaction (rendering user-provided markdown or code blocks without filtering language names), and the attacker cannot directly exfiltrate data or achieve code execution—instead, injected properties cause logic errors, denial of service, or application crashes. Patches are available in versions 9.18.2, 10.1.2, and all newer releases.
Affected products
- highlight.js highlight.js before 9.18.2, and 10.0.0 to 10.1.1
Timeline
- 2020-11-24: disclosed
- 2020-11-24: patched: Versions 9.18.2 and 10.1.2 released with fixes