Executive brief
Slashify is an Express middleware that removes trailing slashes from URLs to normalize routes. The middleware fails to validate redirect destinations, allowing attackers to craft URLs with double slashes that bypass URL parsing and redirect users to arbitrary external domains. This could be exploited to redirect users to phishing sites or malicious domains, damaging user trust.
Technical details
The vulnerability is an open redirect (CWE-601) in the Slashify Express middleware. The middleware strips trailing slashes from request paths and redirects users to the normalized URL, but does not validate the destination path. By crafting a URL with a double slash prefix (e.g., `localhost:3000///github.com/`), the browser interprets the URL as a protocol-relative redirect to an external domain (e.g., `https://github.com`). The vulnerability requires user interaction (clicking a malicious link) but is network-reachable with no authentication required. An attacker can redirect users to arbitrary domains. The vulnerability remains unpatched in all versions of Slashify (up to 1.0.0), and the package maintainer recommends discontinuing use entirely.
Affected products
- Divshot Slashify up to 1.0.0
Timeline
- 2021-02-05: disclosed: Published to GitHub Advisory Database
- 2021-02-19: other: Recorded in NVD
- 2021-04-01: other: Referenced in NetApp advisory