Junglewise Threat Intelligence

CVE-2024-41677: Qwik mutation XSS due to improper HTML escaping in SSR

CVE-2024-41677 · Severity: low · CVSS 3.1 · Published 2024-08-06

Technologies: @builder.io/qwik (npm). Vendors: npm.

Executive brief

Qwik, a web framework used for building high-performance applications, is vulnerable to a type of security flaw called mutation Cross-Site Scripting (mXSS). This occurs because the framework does not properly clean up user-provided data when generating web pages on the server. An attacker could use this to run malicious scripts in a user's browser, potentially leading to unauthorized actions or the theft of sensitive session information.

Technical details

A mutation Cross-Site Scripting (mXSS) vulnerability exists in Qwik's server-side rendering (SSR) engine. The root cause is improper HTML escaping in `render-ssr.ts`, where certain characters (like quotes and ampersands) are escaped for attributes, but other critical characters like less-than (<) and greater-than (>) signs are not consistently handled in all contexts. This discrepancy allows an attacker to provide input that, when processed by the browser's DOM parser (specifically within elements like <noscript>), 'mutates' into executable script tags. The attack is delivered via a network request (e.g., a malicious URL parameter) and requires a user to visit the crafted link. The vulnerability is fixed in Qwik version 1.6.0 and @builder.io/qwik version 1.7.3.

Affected products

  • QwikDev qwik < 1.6.0
  • QwikDev @builder.io/qwik < 1.7.3

Timeline

  • 2024-08-06: advisory
  • 2024-08-06: disclosed
  • 2024-06-25: patched

References

Related threats