Executive brief
webmention.js is a JavaScript library used to display webmention comments and reactions on web pages. A cross-site scripting (XSS) vulnerability in versions prior to 0.5.5 allows attackers to inject malicious code through improperly escaped webmention properties, potentially compromising the integrity of websites and stealing visitor data.
Technical details
The vulnerability is a stored cross-site scripting (XSS) flaw (CWE-79) caused by insufficient HTML entity escaping of the p-name property in webmention data. The vulnerable component is the webmention rendering logic in static/webmention.js around line 330. An attacker can inject JavaScript through a malicious webmention by crafting a p-name property that is not properly escaped when inserted into the DOM. Network access is required to send a malicious webmention; no authentication is needed. Successful exploitation allows arbitrary JavaScript execution in the context of the affected website's domain. The issue is fixed in version 0.5.5 and later, with improved HTML entity escaping applied across webmention properties.
Affected products
- PlaidWeb webmention.js prior to 0.5.5
Timeline
- 2023-07-14: disclosed
- 2023-07-14: patched: Version 0.5.5 released with XSS mitigation