Junglewise Threat Intelligence

CVE-2024-51091: seajs DOM Clobbering cross-site scripting

CVE-2024-51091 · Severity: medium · CVSS 4 · Published 2025-03-03

Vendors: npm.

Executive brief

seajs is a popular JavaScript module loader used in web applications to dynamically load additional scripts. A vulnerability in how seajs determines the base URL for loading modules allows attackers to inject malicious script-loading directives via specially crafted HTML elements, leading to arbitrary script execution and full compromise of affected websites. This impacts any web application using seajs where user-controlled HTML (like forum posts or comments) can be injected.

Technical details

The vulnerability is a DOM Clobbering attack (CWE-79) in seajs's util-path.js module, specifically in code that retrieves the loader script by accessing document.scripts. An attacker can shadow the document.scripts global by injecting non-script HTML elements (e.g., <img name="scripts">) that exploit the browser's named DOM access mechanism. This replaces the intended script array with attacker-controlled elements, causing seajs to load additional JavaScript from an attacker-controlled URL specified in the src attribute. The attack requires the ability to inject unsanitized HTML tags into a page where seajs is active, but no user interaction or prior authentication is needed. A patched version and complete fix are not yet documented in the advisory.

Affected products

  • seajs seajs 2.2.3 and earlier

Timeline

  • 2025-03-03: disclosed
  • 2025-03-03: advisory

References