Executive brief
sanitize-html is a popular Node.js library used to remove potentially dangerous HTML markup from user-supplied content while preserving safe tags. An attacker can bypass the hostname whitelist protection (allowedIframeHostnames option) by crafting internationalized domain names (IDN), potentially allowing malicious iframes to be embedded in sanitized content. This could lead to XSS attacks or content spoofing if the application relies on the whitelist for security.
Technical details
The vulnerability is an improper input validation issue (CWE-20) in the sanitize-html library before version 2.3.1. The library fails to properly normalize internationalized domain names (IDN) when validating iframe hostnames against the allowedIframeHostnames whitelist. An attacker can supply an IDN-encoded domain that, when interpreted by the browser, resolves to a different domain than what is validated, bypassing the whitelist check. The attack requires no authentication or special preconditions; any application using the allowedIframeHostnames option is potentially vulnerable. The fix was released in version 2.3.1 (January 22, 2021) and normalizes IDN domains before validation.
Affected products
- Apostrophe Technologies sanitize-html before 2.3.1
Timeline
- 2021-02-08: disclosed: CVE-2021-26539 published on NVD
- 2021-01-22: patched: Fix released in version 2.3.1