Executive brief
jQuery UI is a JavaScript library that provides interactive UI widgets, including a Datepicker calendar control used on many websites. The Datepicker widget fails to properly sanitize text options (like button labels and helper text), allowing an attacker to inject malicious scripts that execute when the calendar is initialized with untrusted configuration values. This could lead to session hijacking, credential theft, or malware distribution to website visitors.
Technical details
The vulnerability is a Cross-Site Scripting (XSS) flaw in jQuery UI's Datepicker widget. The affected *Text options (closeText, currentText, prevText, nextText, buttonText, appendText) treat their values as HTML instead of plain text, failing to escape dangerous characters. An attacker who can control these option values—for example, through a configuration API or untrusted data source—can inject JavaScript code that executes in the browser context. The attack requires no authentication and exploits user interaction (opening the datepicker), but the impact is limited to non-critical integrity issues (no data theft or confidentiality loss). The fix was released in jQuery UI 1.13.0, which treats all *Text values as plain text and properly escapes HTML.
Affected products
- jQuery UI before 1.13.0
Timeline
- 2021-10-25: disclosed: GitHub security advisory published
- 2021-10-26: patched: jQuery UI 1.13.0 released with fix