Executive brief
osm-static-maps is a Node.js library that generates static maps from OpenStreetMap data. The package fails to escape user input before inserting it into HTML templates, allowing attackers to inject malicious code. This can lead to cross-site scripting (XSS) attacks when output is displayed in a web browser, or server-side request forgery (SSRF) and local file disclosure when processed server-side.
Technical details
The vulnerability stems from unsanitized user input being passed directly to a template engine with triple-brace syntax ({{{ ... }}}), which bypasses escaping. The affected component is the template handling in osm-static-maps. Attack vectors include both client-side XSS (when output is rendered in a browser) and server-side exploitation via puppeteer (enabling SSRF and local file read). No authentication is required; the vulnerability affects all versions before 3.9.0. The fix involves properly escaping special characters before template insertion, as demonstrated in the upstream patch (PR #24).
Affected products
- jperelli osm-static-maps < 3.9.0
Timeline
- 2021-05-10: disclosed
- 2020-11-01: patched: Fix merged in PR #24
- 2020-10-20: other: NVD publication date for CVE-2020-7749