Executive brief
Teddy is a templating language used to generate dynamic web content. The library failed to properly escape HTML special characters when template variables contained array values instead of strings, allowing attackers to inject malicious JavaScript that would execute in users' browsers. This could enable session hijacking, credential theft, or malware delivery.
Technical details
A type confusion vulnerability in the escapeEntities function allowed input sanitization to be bypassed when model content was an array rather than a string. When a template variable was populated with an array value, the HTML entity escaping logic failed to process it, resulting in unescaped HTML/JavaScript being rendered directly into the output. The vulnerability affected all versions before 0.5.9 and required user interaction (visiting a page with the vulnerable template). An attacker could craft malicious template data to execute arbitrary JavaScript in a victim's browser context, potentially stealing session tokens or performing actions on their behalf. The fix, released in version 0.5.9, refactored the escape entities function to properly validate input types before processing.
Affected products
- rooseveltframework teddy <0.5.9
Timeline
- 2021-09-01: disclosed: Vulnerability disclosed to Snyk
- 2021-10-07: advisory: CVE-2021-23447 published
- 2021-10-07: patched: Version 0.5.9 released with fix