Junglewise Threat Intelligence

CVE-2022-25929: Smoothie Cross-site Scripting in tooltipLabel and strokeStyle

CVE-2022-25929 · Severity: low · CVSS 3.1 · Published 2022-12-21

Vendors: npm.

Executive brief

Smoothie is a JavaScript charting library used to render real-time data visualizations in web applications. A cross-site scripting (XSS) vulnerability exists when application code allows users to control the tooltipLabel or strokeStyle properties without sanitization, enabling attackers to inject and execute arbitrary JavaScript in the context of a victim's browser session.

Technical details

Smoothie versions 1.31.0 through 1.36.0 are vulnerable to stored or reflected XSS (CWE-79) due to improper input sanitization in the strokeStyle and tooltipLabel properties. The vulnerability stems from unsafe use of innerHTML when rendering these user-controlled values without escaping HTML special characters. Exploitation requires that application developers allow end users to control these properties, which is a plausible scenario in dynamic charting applications. An attacker can inject malicious HTML/JavaScript payloads via these properties to steal session tokens, redirect users, or perform actions on their behalf. The vulnerability is fixed in version 1.36.1, which implements proper sanitization of user input before rendering.

Affected products

  • Smoothie Smoothie 1.31.0 through 1.36.0

Timeline

  • 2022-12-21: disclosed
  • 2022-05-16: patched: Fix merged to joewalnes/smoothie master branch

References