Junglewise Threat Intelligence

CVE-2021-23416: curly-bracket-parser cross-site scripting in template parsing

CVE-2021-23416 · Severity: low · CVSS 3.1 · Published 2021-08-10

Vendors: npm.

Executive brief

curly-bracket-parser is a JavaScript library used to process template strings by replacing variables inside templates. When used as a template engine, it fails to properly sanitize user-supplied input, allowing attackers to inject malicious scripts that execute in a victim's browser if they view a page containing the unsanitized template output.

Technical details

This is a stored/reflected cross-site scripting (XSS) vulnerability in curly-bracket-parser caused by insufficient input sanitization when parsing template strings. The vulnerability affects all versions through 1.0.2. An attacker can inject arbitrary JavaScript code via crafted template input; when a page renders this output without additional escaping, the JavaScript executes in the context of the user's browser (CWE-79). The attack requires user interaction (viewing a page with the vulnerable content) but no authentication. A fix would involve properly escaping or sanitizing user input during template processing.

Affected products

  • magynhard curly-bracket-parser through 1.0.2

Timeline

  • 2021-08-10: disclosed
  • 2021-07-28: other: CVE published on NVD

References