Executive brief
The Nextcloud dialogs library is a JavaScript component used by Nextcloud applications to display notification messages (toasts) to users. Insufficient input escaping in this library allows attackers to inject malicious scripts into toast notifications if user-supplied input is displayed without proper sanitization. While Nextcloud Server itself mitigates this risk through strict Content Security Policy, other applications using this library could be vulnerable to account takeover or data theft if user input reaches toast messages.
Technical details
A cross-site scripting (XSS) vulnerability exists in the @nextcloud/dialogs library due to improper neutralization of script-related HTML tags in toast notification text. The vulnerable component fails to escape user-supplied input before rendering it in toast messages, allowing attackers to inject arbitrary HTML and JavaScript. The attack requires the vulnerable application to display user-controlled data in a toast without prior sanitization. An authenticated attacker or a compromised website could inject malicious scripts to execute arbitrary code in the context of the application. The vulnerability was patched in version 3.1.2 with improved input escaping; applications can also explicitly use the options.isHTML flag only when displaying trusted HTML content.
Affected products
- Nextcloud dialogs < 3.1.2
Timeline
- 2021-04-13: disclosed
- 2021-04-16: advisory
- 2021-04-13: patched: Patched in version 3.1.2