Junglewise Threat Intelligence

CVE-2021-3377: drudru ansi_up cross-site scripting in hyperlink handling

CVE-2021-3377 · Severity: low · CVSS 3.1 · Published 2021-03-11

Vendors: npm.

Executive brief

The ansi_up library, which converts terminal text (ANSI codes) into web-friendly HTML, contains a security flaw in how it handles hyperlinks. An attacker can use specially crafted text to execute malicious scripts in a user's browser when that text is displayed. This could lead to unauthorized actions being performed in the user's session or the theft of sensitive information.

Technical details

A cross-site scripting (XSS) vulnerability exists in ansi_up v4 and earlier. The library supports converting ANSI escape codes into HTML hyperlinks; however, it fails to properly sanitize URLs within the Operating System Command (OSC) sequence. An attacker can provide a malformed URL containing malicious JavaScript, which is then rendered into the HTML output without adequate escaping. This allows for the execution of arbitrary scripts in the context of the user's browser (CWE-79). The issue was addressed in version 5.0.0 by making HTML escaping mandatory and removing the 'escape_for_html' configuration property.

Affected products

  • drudru ansi_up < 5.0.0

Timeline

  • 2021-01-29: patched: Fix committed in version 5.0.0
  • 2021-03-05: advisory: NVD published CVE-2021-3377
  • 2021-03-11: disclosed: GitHub Advisory published

References