Junglewise Threat Intelligence

CVE-2023-3481: Critters cross-site scripting in HTML parsing

CVE-2023-3481 · Severity: low · CVSS 3.1 · Published 2023-08-11

Vendors: npm.

Executive brief

Critters is a JavaScript library used to inline critical CSS for faster web page rendering. A cross-site scripting (XSS) vulnerability in versions 0.0.17–0.0.19 allows attackers to inject malicious scripts through improper HTML parsing, potentially enabling account compromise or data theft from affected websites.

Technical details

The vulnerability is a reflected/stored XSS flaw (CWE-79, CWE-80) caused by improper neutralization of script-related HTML tags during HTML parsing. The affected versions (0.0.17–0.0.19) fail to correctly escape or encode user-controlled or untrusted HTML input, allowing attackers to inject arbitrary JavaScript. The attack requires user interaction (e.g., visiting a malicious page or clicking a link). An attacker can craft a malicious HTML document that, when processed by Critters, will execute arbitrary JavaScript in the context of the victim's browser, leading to session hijacking, credential theft, or malware delivery. The fix is available in v0.0.20 and later.

Affected products

  • GoogleChromeLabs Critters 0.0.17–0.0.19

Timeline

  • 2023-08-11: disclosed: Security advisory published
  • 2023-08-11: patched: Fix released in v0.0.20

References