Executive brief
url-parse is a JavaScript library used to parse and extract components from URLs in web applications. Versions before 1.5.0 incorrectly interpret certain malformed URLs containing backslashes (such as "http:/\") as relative paths rather than absolute URLs, potentially allowing an attacker to bypass path validation or access unintended resources through path traversal.
Technical details
The vulnerability is a path traversal flaw (CWE-23) in url-parse versions 0.1.0 through 1.4.7 caused by improper handling of backslash characters in URL parsing. The library uses a custom MOARE regex parser that fails to correctly reject or normalize backslashes in URLs, causing them to be misinterpreted as relative paths rather than invalid URI components. This affects any application using url-parse to validate, normalize, or route URLs; an attacker can craft a malicious URL with backslashes to bypass security checks or access unintended paths. The vulnerability requires only network access and has no authentication or user interaction prerequisites. The fix was released in version 1.5.0.
Affected products
- unshiftio url-parse 0.1.0 through 1.4.7
Timeline
- 2021-05-06: disclosed
- 2021-05-06: patched: Version 1.5.0 released