Executive brief
RSSHub, an open-source tool used to generate RSS feeds from various websites, contains a security vulnerability in its internal media proxy. An attacker can create a malicious link that, when clicked by a user, executes unauthorized scripts in the user's browser. This could lead to the theft of session information or unauthorized actions being performed on behalf of the user.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in RSSHub's internal media proxy. The component fails to properly validate or sanitize content when proxying specially crafted images, allowing an attacker to inject and execute arbitrary JavaScript code in the context of the RSSHub domain. The attack is delivered via a network request to a maliciously constructed URL and requires a user to interact with that URL. The vulnerability was addressed by removing the internal media proxy feature in version 1.0.0-master.d8ca915 (commit 4d3e5d7).
Affected products
- DIYgod RSSHub >= 1.0.0-master.cbbd829, < 1.0.0-master.d8ca915
Timeline
- 2024-03-05: advisory: Vendor advisory published on GitHub
- 2024-03-06: disclosed: Public disclosure via GHSA
- 2024-03-21: other: NVD publication date