Junglewise Threat Intelligence

CVE-2024-43799: send template injection leading to XSS

CVE-2024-43799 · Severity: low · CVSS 3.1 · Published 2024-09-10

Vendors: Pillarjs.

Executive brief

send is a Node.js library used to serve static files and handle HTTP redirects in web applications. The vulnerability allows attackers to inject malicious template code through redirect URLs, enabling them to execute arbitrary JavaScript in users' browsers. Exploitation requires attackers to control the redirect input and victims must click a link in a template before the browser completes the redirect.

Technical details

The vulnerability is a template injection flaw (CWE-79) in the send library's redirect handling mechanism. When untrusted user input is passed to SendStream.redirect(), the library fails to properly sanitize template expressions, allowing XSS payload injection. Attack requires control over the redirect URL parameter, no authentication, network reachability, and user interaction (clicking a link). The attacker must also ensure the application does not redirect before the template is rendered. Patches are available in send version 0.19.0 and later.

Affected products

  • pillarjs send before 0.19.0

Timeline

  • 2024-09-10: disclosed
  • 2024-09-10: patched: Version 0.19.0 released

References