Junglewise Threat Intelligence

CVE-2023-26140: Excalidraw Cross-site Scripting in canvas element links

CVE-2023-26140 · Severity: low · CVSS 3.1 · Published 2023-08-16

Technologies: @excalidraw/excalidraw (npm), Excalidraw. Vendors: npm, Excalidraw.

Executive brief

Excalidraw is a popular open-source drawing application. The library improperly sanitizes URLs attached to canvas elements, allowing attackers to inject malicious scripts. Users who share drawings containing malicious links with others could enable attackers to steal data or perform actions on behalf of victims.

Technical details

This is a Cross-site Scripting (CWE-79) vulnerability in @excalidraw/excalidraw prior to version 0.15.3, caused by improper neutralization of URLs in canvas element links. The vulnerability requires network access and user interaction (the victim must open a shared drawing with a malicious link). An attacker can craft a drawing with a specially-crafted URL that executes arbitrary JavaScript in the victim's browser, allowing data exfiltration or session hijacking. The vulnerability is only exploitable when untrusted user input is accepted in drawings that are shared with others. A patch is available in version 0.15.3 and later.

Affected products

  • Excalidraw excalidraw prior to 0.15.3

Timeline

  • 2023-08-16: disclosed
  • 2023-08-16: patched: Version 0.15.3 released with patch

References

Related threats