Executive brief
Highlight.run is a session recording and analytics library used to capture user interactions on websites. The library failed to obfuscate passwords when an HTML password input field was dynamically converted to a text input via JavaScript "Show Password" buttons, potentially recording sensitive credentials in plaintext during replay. While the vendor added server-side password filtering as a workaround, the client-side vulnerability could expose passwords in network transmission and session recordings until patched.
Technical details
The vulnerability is a sensitive data exposure flaw (CWE-319) in the session recording functionality of highlight.run. The library tracks DOM modifications and records all input changes; however, it failed to maintain obfuscation metadata when an input element's type attribute was changed from "password" to "text" dynamically. An attacker or compromised web page could trigger a "Show Password" UI pattern that converts a password input to text, after which the library would record the plaintext password value in its session replay logs. This requires high privileges (admin control over the web page), user interaction (clicking the show/hide button), and network reachability. The issue was patched in version 6.0.0 by tracking type attribute changes to preserve obfuscation rules for inputs that were originally password fields.
Affected products
- Highlight highlight.run before 6.0.0
Timeline
- 2023-05-25: disclosed
- 2023-05-26: patched: highlight.run version 6.0.0