Executive brief
Tagify is a popular JavaScript library used to render input and tag selection UI components in web applications. An attacker can inject malicious code through the placeholder parameter, causing arbitrary JavaScript to execute in a user's browser when they interact with the component. This can lead to account compromise, credential theft, or malware distribution.
Technical details
This is a stored/reflected cross-site scripting (XSS) vulnerability (CWE-79) in the @yaireo/tagify library before version 4.9.8. The vulnerability exists in the template wrapper component, where user-supplied placeholder values are not properly sanitized before being rendered into the DOM. An attacker can craft a malicious placeholder string containing JavaScript code (e.g., event handlers or script tags) that executes when the component is rendered. The attack requires user interaction (UI:R) but no authentication, and affects the confidentiality and integrity of user sessions (C:L/I:L). The fix was released in version 4.9.8.
Affected products
- yairEO tagify before 4.9.8
Timeline
- 2022-04-30: disclosed
- 2022-04-29: patched: Fix released in version 4.9.8