Junglewise Threat Intelligence

CVE-2022-29230: Shopify Hydrogen cross-site scripting in hydrating data

CVE-2022-29230 · Severity: low · CVSS 3.1 · Published 2022-05-19

Vendors: Shopify, npm.

Executive brief

Hydrogen is a framework for building storefronts powered by Shopify. A cross-site scripting vulnerability allows attackers to inject and execute arbitrary scripts on pages built with Hydrogen when user-controlled data is used during hydration, potentially stealing customer credentials, session tokens, or personal information.

Technical details

This is a cross-site scripting (XSS) vulnerability (CWE-79) in Shopify's Hydrogen framework that affects versions 0.10.0 through 0.18.0. The vulnerability exists in the hydrating data processing logic; when hydration data is sourced from user input, an attacker can inject malicious scripts that execute in the browser context of other users visiting pages built with affected Hydrogen versions. The attack requires no authentication and is network-accessible. An attacker can execute arbitrary JavaScript, potentially stealing session tokens, harvesting sensitive data, or performing actions on behalf of legitimate users. The vulnerability is patched in version 0.19.0; no workaround is available, and Content Security Policy does not effectively mitigate the issue.

Affected products

  • Shopify Hydrogen 0.10.0 to 0.18.0

Timeline

  • 2022-05-19: disclosed
  • 2022-05-19: patched: Fixed in version 0.19.0

References