Executive brief
URIjs is a JavaScript library used to parse and manipulate URLs in web applications. The library incorrectly handles backslash characters in URLs, allowing attackers to spoof the hostname component. If an application relies on URIjs to validate or enforce security policies based on hostname (such as allow/block lists or access controls), an attacker could bypass these protections, potentially leading to unauthorized access or redirects to malicious sites.
Technical details
The vulnerability is an improper input validation issue (CWE-20) in URL parsing where backslashes in the scheme delimiter are not properly handled. Affected versions of URIjs parse URLs like "https:/\expected-example.com" as having no hostname, whereas the correct behavior (per WHATWG URL specification) is to extract "expected-example.com". The attack vector is network-based with no authentication or user interaction required—an attacker simply crafts a malicious URL and causes an application using URIjs to parse it. Depending on how the application uses the parsed hostname, impacts include bypass of security allow/block lists, Server-Side Request Forgery (SSRF) attacks, and open redirects. Version 1.19.6 and later patch this issue to align with WHATWG URL specification compliance and browser behavior.
Affected products
- medialize URIjs before 1.19.6
Timeline
- 2021-02-22: disclosed
- 2021-03-01: advisory
- 2021: patched: Version 1.19.6 released with fix