Executive brief
Pagefind is a static site search library that dynamically loads JavaScript and WebAssembly files. An attacker who can inject benign HTML (such as an image tag with a name attribute) can trick the library into loading dependencies from an attacker-controlled external domain, enabling a cross-site scripting (XSS) attack. This escalates limited HTML injection capabilities into full JavaScript execution.
Technical details
The vulnerability is a DOM clobbering attack (CWE-79: Cross-site Scripting) in Pagefind's initialization logic. Pagefind locates its dynamic files by reading document.currentScript.src, but an attacker can create an HTML element (e.g., <img name="currentScript">) to clobber this property and redirect it to an attacker-controlled URL. Preconditions include: the attacker must be able to inject arbitrary HTML into the target page (a weaker capability than script injection), and the page must load Pagefind. When triggered, the attacker achieves arbitrary JavaScript execution in the victim's browser. The fix (version 1.1.1 and later) validates that currentScript resolves from an actual script element, preventing the clobbering attack.
Affected products
- CloudCannon pagefind before 1.1.1
- CloudCannon @pagefind/default-ui before 1.1.1
- CloudCannon @pagefind/modular-ui before 1.1.1
Timeline
- 2024-09-03: disclosed
- 2024-09-03: patched: Version 1.1.1 released with fix