Executive brief
sanitize-html is a widely-used Node.js library that removes potentially dangerous HTML and CSS from user-supplied content. When the style attribute is allowed and the library is used on a backend server, an attacker can craft CSS rules that leak information about the server's filesystem and installed dependencies. This allows reconnaissance of the target environment and could inform follow-up attacks.
Technical details
sanitize-html versions before 2.12.1 fail to properly sanitize CSS in the style attribute when PostCSS processes source maps. An attacker can inject CSS that uses URL references or other techniques to enumerate local files and directory structures on the backend server. The vulnerability requires that (1) the style attribute is explicitly allowed in the sanitizer configuration, and (2) the application processes user-supplied HTML on a backend server rather than in a browser. Exploitation reveals filesystem paths and dependency information without authentication. The fix in version 2.12.1 ignores source maps during PostCSS processing to prevent this leak.
Affected products
- npm sanitize-html before 2.12.1
Timeline
- 2024-02-24: disclosed: GHSA-rm97-x556-q36h and CVE-2024-21501 published
- 2024-02-22: patched: Fix merged in PR #650 for version 2.12.1