Junglewise Threat Intelligence

CVE-2024-53388: Mavo DOM Clobbering in plugin loading mechanism

CVE-2024-53388 · Severity: medium · CVSS 4 · Published 2025-03-03

Vendors: npm.

Executive brief

Mavo is a web development library that allows users to create data-driven websites using only HTML and CSS. A vulnerability in how the library loads plugins allows an attacker to trick the software into loading malicious scripts from an external server. This could lead to unauthorized code execution (Cross-Site Scripting) on websites using the affected version of the library, potentially compromising user data or site integrity.

Technical details

A DOM Clobbering vulnerability exists in Mavo v0.3.2 within its plugin-loading mechanism. The library uses 'document.currentScript' to determine the base URL for loading dependencies. An attacker can inject a non-script HTML element (such as an <img> tag with name='currentScript') to shadow the legitimate 'document.currentScript' property. By controlling the 'src' attribute of the clobbered element, the attacker can redirect the library to load plugin dependencies from an attacker-controlled domain, resulting in Cross-Site Scripting (XSS). A fix involves verifying that 'document.currentScript' actually refers to a SCRIPT element before accessing its attributes.

Affected products

  • mavoweb mavo 0.3.2

Timeline

  • 2025-03-03: advisory: GHSA-3mf5-r4hg-hfx9 published
  • 2025-03-03: disclosed: CVE-2024-53388 published

References