Executive brief
ReLaXed is a tool for converting markup documents to PDF. A cross-site scripting vulnerability in its Pug-to-PDF converter component allows an attacker with local access to inject malicious scripts that could be executed when processing documents, potentially leading to unauthorized actions or data exposure depending on the processing context.
Technical details
A cross-site scripting (CWE-79) vulnerability exists in ReLaXed's Pug to PDF Converter component affecting versions up to 0.2.2 (last affected 0.2.5). The vulnerability stems from improper input sanitization in an unknown function, allowing manipulation of the conversion process to inject malicious script content. The attack requires local access and no user interaction or special privileges beyond those needed to invoke the tool. An attacker can craft a malicious Pug template that executes arbitrary JavaScript during PDF generation. The vulnerability has been disclosed publicly and proof-of-concept details exist.
Affected products
- RelaxedJS ReLaXed up to 0.2.5
Timeline
- 2024-09-27: disclosed