Junglewise Threat Intelligence

CVE-2024-32472: Excalidraw stored cross-site scripting in web embed component

CVE-2024-32472 · Severity: low · CVSS 3.1 · Published 2024-04-17

Technologies: Excalidraw. Vendors: Excalidraw.

Executive brief

Excalidraw is a popular open-source whiteboarding and diagramming tool used for creating collaborative drawings. A stored cross-site scripting (XSS) vulnerability in its web embed component allows attackers to inject malicious JavaScript code that executes in the context of the hosting domain, potentially compromising user sessions and enabling data theft or defacement of drawings.

Technical details

The vulnerability stems from improper sanitization in Excalidraw's web embed component when handling iframe srcdoc attributes and HTML attributes. An attacker can craft a malicious embed URL containing script tags that bypass sanitization filters, allowing arbitrary JavaScript execution in the same origin. The root cause involved rendering untrusted strings directly as iframe srcdoc content and inadequate attribute-level HTML injection prevention. The attack requires user interaction (inserting an embed into a canvas) but no authentication. Patches were released in versions 0.16.4 and 0.17.6, fixing sanitization logic and restricting the allow-same-origin sandbox flag to only cases that require it.

Affected products

  • Excalidraw excalidraw 0.16.0 to 0.17.5 (patched in 0.16.4 and 0.17.6)

Timeline

  • 2024-04-17: disclosed: Vulnerability published as GHSA-m64q-4jqh-f72f and CVE-2024-32472
  • 2024-04-17: patched: Fixed in versions 0.16.4 and 0.17.6

References

Related threats