Junglewise Threat Intelligence

CVE-2024-43800: serve-static template injection leading to XSS

CVE-2024-43800 · Severity: low · CVSS 3.1 · Published 2024-09-10

Executive brief

serve-static is a Node.js middleware used to serve static files in Express web applications. A template injection vulnerability in the redirect() function can allow attackers to execute arbitrary code in users' browsers if the application passes untrusted input to the redirect function without proper validation. Successful exploitation requires an attacker to control the redirect input, the browser to delay redirecting, and a user to click a malicious link.

Technical details

The vulnerability is a template injection (CWE-79: Cross-site Scripting) in the serve-static middleware's redirect() function. When untrusted user input is passed to response.redirect() without proper validation, it can be injected into a server-side template, leading to arbitrary code execution. The attack requires the attacker to control the redirect parameter, the server to delay the redirect response, the browser to not immediately redirect away, and explicit user interaction (clicking a link). The vulnerability affects serve-static versions before 1.16.0 and versions 2.0.0 through 2.0.x before 2.1.0. Patches are available in serve-static 1.16.0 and 2.1.0.

Affected products

  • Express.js serve-static < 1.16.0, >= 2.0.0 < 2.1.0

Timeline

  • 2024-09-10: disclosed
  • 2024-09-10: patched: Fixed in serve-static 1.16.0 and 2.1.0

References