Junglewise Threat Intelligence

CVE-2021-23648: Braintree sanitize-url Cross-site Scripting

CVE-2021-23648 · Severity: low · CVSS 3.1 · Published 2022-03-17

Vendors: npm.

Executive brief

The sanitize-url library is a JavaScript utility that removes potentially dangerous content from URLs to prevent them from executing malicious code when rendered in web pages. A flaw in versions before 6.0.0 allowed specially crafted HTML-encoded URLs to bypass the sanitization checks, enabling attackers to inject and execute malicious scripts if a user visits a manipulated link. This could allow attackers to steal user credentials, session tokens, or other sensitive data.

Technical details

The vulnerability is a Cross-site Scripting (XSS) flaw in the sanitizeUrl function caused by improper handling of HTML-encoded URLs. The root cause is that the function did not decode HTML entities before sanitization, allowing attackers to bypass the security filter using encoded payloads. When URLs are HTML-encoded and rendered as HTML from a server (rather than dynamically created via the DOM API), the encoded characters are decoded without sanitization occurring first. The attack requires user interaction (visiting a malicious link) and is network-reachable. An attacker can inject arbitrary JavaScript that executes in the victim's browser context. The vulnerability was fixed in version 6.0.0 by decoding HTML entities before sanitizing the URL.

Affected products

  • Braintree sanitize-url before 6.0.0

Timeline

  • 2022-03-16: disclosed: NVD published CVE-2021-23648
  • 2022-03-17: advisory: GHSA-hqq7-2q2v-82xq published
  • 2022-03-01: patched: Fix merged in PR #40 for version 6.0.0

References

Related threats