Junglewise Threat Intelligence

CVE-2022-0776: reveal.js cross-site scripting in speaker view

CVE-2022-0776 · Severity: low · CVSS 3.1 · Published 2022-03-02

Vendors: npm.

Executive brief

reveal.js is a popular open-source presentation framework used to create and display slideshows in web browsers. A cross-site scripting (XSS) vulnerability in the speaker notes feature allows an attacker to inject malicious code that executes in a victim's browser, potentially stealing session data, capturing keyboard input, or defacing the presentation content.

Technical details

The vulnerability is a DOM-based cross-site scripting (CWE-79) flaw in the speaker-view.html plugin component. The onmessage event listener does not validate the origin of postMessage events before processing the content, allowing any attacker-controlled origin to send malicious messages to the window. An attacker can craft a malicious webpage that sends postMessage events with JavaScript code to a browser window hosting reveal.js, resulting in arbitrary code execution in the context of the victim's domain. The fix adds an origin check (window.location.origin !== event.origin) before processing incoming messages. The vulnerability affects all versions prior to 4.3.0.

Affected products

  • Hakim El Hattab reveal.js before 4.3.0

Timeline

  • 2022-03-01: disclosed: NVD publication date
  • 2022-03-02: patched: Fix committed to repository, version 4.3.0 released
  • 2022-03-02: advisory: GHSA advisory published

References

Related threats