Executive brief
op-browser is a software library used to automate or open web browsers from within applications. A critical security flaw allows an attacker to execute unauthorized commands on the underlying operating system by providing a specially crafted URL. This could lead to a complete takeover of the system where the application is running, potentially resulting in data theft or service disruption.
Technical details
The op-browser package through version 1.0.9 is vulnerable to OS command injection (CWE-78). The vulnerability exists in the 'url' function within 'lib/index.js', where user-supplied input is improperly neutralized before being used to construct a system command. An attacker can exploit this by passing malicious shell characters within a URL string. This allows for unauthenticated, remote execution of arbitrary commands with the privileges of the application process. As of the latest advisory update, no patched versions are available.
Affected products
- hiproxy op-browser <= 1.0.9
Timeline
- 2020-04-02: disclosed: NVD publication date
- 2022-02-10: advisory: GitHub Advisory published