Executive brief
edge.js is a Node.js template engine used to render dynamic HTML pages in web applications. A type confusion vulnerability allows attackers to bypass input sanitization by passing malicious content as an array instead of a string, enabling the injection of unescaped JavaScript code that executes in users' browsers. This could allow attackers to steal session cookies, hijack user accounts, or redirect users to malicious sites.
Technical details
edge.js before version 5.3.2 contains a type confusion vulnerability in its input sanitization logic. When user-supplied data is passed to the template renderer as an array (instead of a string or SafeValue object), the sanitization checks are bypassed, allowing raw HTML and JavaScript to pass through unescaped into the rendered output. The vulnerability affects the core templating engine regardless of whether safe escaping syntax ({{ }}) is used. An attacker can exploit this by crafting input containing script tags or event handlers (e.g., <img src=x onerror='alert(1)' />) wrapped in an array, which will be rendered verbatim into the HTML response. The fix was implemented in version 5.3.2 and involves proper type checking and consistent sanitization across different input types. No authentication or special privileges are required to exploit this vulnerability.
Affected products
- edge-js edge.js < 5.3.2
Timeline
- 2021-09-01: disclosed
- 2021-09-21: advisory
- 2021-09-22: patched