Junglewise Threat Intelligence

CVE-2024-21485: Plotly Dash Cross-site Scripting in anchor tag href

CVE-2024-21485 · Severity: medium · CVSS 6.5 · Published 2024-02-02

Vendors: npm, PyPI.

Executive brief

Plotly Dash is a Python framework for building data visualization dashboards. The framework is vulnerable to cross-site scripting (XSS) when href attributes in links, iframes, and forms are populated with untrusted user data. An authenticated attacker who stores malicious JavaScript in a shared view could execute arbitrary code in the browsers of other users who access that view, potentially stealing sensitive data or session tokens.

Technical details

The vulnerability exists in multiple Dash component packages (dash, dash-core-components, dash-html-components) where URL properties such as href, src, data, action, and formAction are not validated before rendering. When these properties accept user-controlled input (particularly through stored view mechanisms), an attacker can inject javascript: URIs or other XSS payloads. The affected properties include dcc.Link.href, html.A.href, html.Iframe.src, html.ObjectEl.data, html.Embed.src, html.Button.formAction, and html.Form.action. Exploitation requires authentication and a Dash application that persists user input for other users to view. An attacker with such access can execute arbitrary JavaScript in victims' browsers, potentially harvesting sensitive data, stealing access tokens, or performing actions as the victim. Patches sanitize these properties and were released in Dash 2.15.0, dash-core-components 2.0.0/2.13.0, and dash-html-components 2.0.0/2.0.16.

Affected products

  • Plotly Dash < 2.15.0
  • Plotly dash-core-components < 2.0.0; < 2.13.0 (npm)
  • Plotly dash-html-components < 2.0.0; < 2.0.16 (npm)

Timeline

  • 2024-02-02: disclosed: Published to GitHub Advisory Database and NVD
  • 2024-01-30: patched: Fix merged in PR #2732; releases: Dash 2.15.0, dash-core-components 2.0.0/2.13.0, dash-html-components 2.0.0/2.0.16

References