Executive brief
Excalidraw is a popular open-source drawing application. The library improperly sanitizes URLs attached to canvas elements, allowing attackers to inject malicious scripts. Users who share drawings containing malicious links with others could enable attackers to steal data or perform actions on behalf of victims.
Technical details
This is a Cross-site Scripting (CWE-79) vulnerability in @excalidraw/excalidraw prior to version 0.15.3, caused by improper neutralization of URLs in canvas element links. The vulnerability requires network access and user interaction (the victim must open a shared drawing with a malicious link). An attacker can craft a drawing with a specially-crafted URL that executes arbitrary JavaScript in the victim's browser, allowing data exfiltration or session hijacking. The vulnerability is only exploitable when untrusted user input is accepted in drawings that are shared with others. A patch is available in version 0.15.3 and later.
Affected products
- Excalidraw excalidraw prior to 0.15.3
Timeline
- 2023-08-16: disclosed
- 2023-08-16: patched: Version 0.15.3 released with patch