Executive brief
tempura is a JavaScript template library used to render dynamic content in web applications. A flaw in its escape function allows attackers to inject malicious scripts by passing arrays as input, which bypass HTML sanitization and execute in users' browsers. This can lead to session theft, credential harvesting, or defacement of web pages served by applications using this library.
Technical details
The vulnerability is a cross-site scripting (XSS) flaw in tempura's esc function (CWE-79). When the input to esc is of type object (specifically an array), the function returns the input unsanitized instead of escaping HTML special characters. The attack is network-accessible and requires no authentication but does require user interaction (e.g., clicking a link or viewing a crafted page). An attacker can exploit this to inject arbitrary JavaScript that executes in the context of a vulnerable application. The issue was fixed in version 0.4.0, which ensures esc always returns a properly escaped string.
Affected products
- lukeed tempura before 0.4.0
Timeline
- 2021-11-08: disclosed
- 2021-11-04: patched: fix commit available