Executive brief
sanitize-url is a JavaScript library used to prevent malicious links from being used in web applications. An attacker can bypass the URL sanitization by encoding malicious content as HTML entities (such as encoded colons or tabs), allowing them to execute arbitrary JavaScript code in users' browsers. This could lead to session hijacking, credential theft, or malware installation.
Technical details
The vulnerability is a Cross-Site Scripting (XSS) vulnerability caused by improper handling of HTML entities in URL sanitization. The vulnerable component fails to decode and re-validate HTML-encoded characters (particularly colons and tabs) before performing URL scheme validation, allowing attackers to bypass the sanitization logic. The attack requires user interaction (the victim must click a malicious link), and is network-accessible with no authentication required. An attacker can craft a URL with HTML-encoded payloads that pass the sanitizer but execute as XSS when rendered in the browser. The vulnerability was fixed in version 6.0.1, as evidenced by commit d4bdc89f1743fe3cdb7c3f24b06e4c875f349b0c.
Affected products
- Braintree sanitize-url before 6.0.1
Timeline
- 2023-02-24: disclosed
- 2023-02-24: patched: Fix released in version 6.0.1