Executive brief
PeerTube is a decentralized video platform allowing users to upload and share content. An attacker can upload a malicious SVG image file and distribute its URL to other users; when recipients open the link, JavaScript embedded in the SVG executes in their browser, allowing the attacker to steal session keys and authentication tokens stored in local storage and hijack user accounts.
Technical details
This is a cross-site scripting (XSS) vulnerability arising from insufficient input sanitization in the image preview feature. Specifically, SVG files uploaded by users are not properly neutralized before being displayed to other users, allowing attackers to embed malicious JavaScript within SVG markup. The attack requires user interaction (opening a link to the malicious preview) and relies on the platform's use of browser local storage for session key storage. An attacker can execute arbitrary JavaScript in the context of a victim's session, leading to session hijacking, credential theft, and account takeover. The vulnerability was fixed in version 3.4.0 through safer image preview handling (commit 0ea2f79d45b301fcd660efc894469a99b2239bf6).
Affected products
- PeerTube PeerTube before 3.4.0
Timeline
- 2021-09-15: disclosed
- 2021-09-08: patched: Fix committed; release version 3.4.0