Executive brief
Qwik, a web framework used for building high-performance applications, is vulnerable to a type of security flaw called mutation Cross-Site Scripting (mXSS). This occurs because the framework does not properly clean up user-provided data when generating web pages on the server. An attacker could use this to run malicious scripts in a user's browser, potentially leading to unauthorized actions or the theft of sensitive session information.
Technical details
A mutation Cross-Site Scripting (mXSS) vulnerability exists in Qwik's server-side rendering (SSR) engine. The root cause is improper HTML escaping in `render-ssr.ts`, where certain characters (like quotes and ampersands) are escaped for attributes, but other critical characters like less-than (<) and greater-than (>) signs are not consistently handled in all contexts. This discrepancy allows an attacker to provide input that, when processed by the browser's DOM parser (specifically within elements like <noscript>), 'mutates' into executable script tags. The attack is delivered via a network request (e.g., a malicious URL parameter) and requires a user to visit the crafted link. The vulnerability is fixed in Qwik version 1.6.0 and @builder.io/qwik version 1.7.3.
Affected products
- QwikDev qwik < 1.6.0
- QwikDev @builder.io/qwik < 1.7.3
Timeline
- 2024-08-06: advisory
- 2024-08-06: disclosed
- 2024-06-25: patched