Executive brief
ArchiveBox is a self-hosted web archiving tool. A security flaw allows malicious code within an archived website to execute with the same permissions as the ArchiveBox administrator if they view the archive while logged in. This could allow an attacker to steal data, modify or delete archives, and gain full control over the ArchiveBox user accounts.
Technical details
ArchiveBox versions prior to 0.9.0 are vulnerable to a Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF) bypass because archived content is served from the same host and port as the admin panel. When an administrator views a malicious snapshot (e.g., captured via wget or DOM extractors), the archived JavaScript executes within the same origin as the management interface. This allows the script to bypass browser SOP/CORS protections and perform administrative actions such as modifying snapshots or managing users. The vulnerability is mitigated in version 0.9.0; workarounds include disabling the WGET and DOM extractors or ensuring administrators are logged out when viewing untrusted archives.
Affected products
- ArchiveBox ArchiveBox < 0.9.0
Timeline
- 2023-10-19: disclosed
- 2023-10-19: advisory
- 2023-10-19: patched: Patched in version 0.9.0
References
- https://github.com/ArchiveBox/ArchiveBox/security/advisories/GHSA-cr45-98w9-gwqx
- https://github.com/ArchiveBox/ArchiveBox/issues/239
- https://en.wikipedia.org/wiki/Cross-site_request_forgery
- https://github.com/ArchiveBox/ArchiveBox
- https://github.com/ArchiveBox/ArchiveBox/wiki/Configuration
- https://github.com/ArchiveBox/ArchiveBox/wiki/Publishing-Your-Archive