Executive brief
curly-bracket-parser is a JavaScript library used to process template strings by replacing variables inside templates. When used as a template engine, it fails to properly sanitize user-supplied input, allowing attackers to inject malicious scripts that execute in a victim's browser if they view a page containing the unsanitized template output.
Technical details
This is a stored/reflected cross-site scripting (XSS) vulnerability in curly-bracket-parser caused by insufficient input sanitization when parsing template strings. The vulnerability affects all versions through 1.0.2. An attacker can inject arbitrary JavaScript code via crafted template input; when a page renders this output without additional escaping, the JavaScript executes in the context of the user's browser (CWE-79). The attack requires user interaction (viewing a page with the vulnerable content) but no authentication. A fix would involve properly escaping or sanitizing user input during template processing.
Affected products
- magynhard curly-bracket-parser through 1.0.2
Timeline
- 2021-08-10: disclosed
- 2021-07-28: other: CVE published on NVD