Executive brief
anchorme is a JavaScript library that automatically converts URLs and email addresses in text into clickable hyperlinks. The library contains a cross-site scripting (XSS) vulnerability in its URL transformation logic that allows attackers to inject malicious scripts through specially crafted URLs. This could enable attackers to steal user session tokens, capture user input, or perform actions on behalf of users viewing content processed by this library.
Technical details
anchorme is vulnerable to stored/reflected XSS via improper sanitization of user input in the URL transformation functionality. The vulnerability exists in the transform.ts file where URL strings are directly interpolated into HTML anchor tag attributes and text content without proper HTML encoding. An attacker can craft a malicious URL string containing JavaScript payloads that will be executed in the browser when the transformed HTML is rendered. The attack requires user interaction (opening or viewing the transformed content) and network accessibility. No authentication is required. Patches or updated versions should be available from the maintainers; users should upgrade to the latest patched version.
Affected products
- anchorme anchorme 0 through 2.1.2
Timeline
- 2021-07-21: disclosed: NVD publication date
- 2021-07-26: advisory: GHSA advisory published