Junglewise Threat Intelligence

CVE-2025-25300: smartbanner.js window.opener vulnerability

CVE-2025-25300 · Severity: medium · CVSS 4 · Published 2019-09-13

Vendors: npm.

Executive brief

smartbanner.js is a library that adds a banner prompting mobile users to install an app. When users click the banner link to open a third-party page, the library failed to prevent access to the original page via window.opener, allowing attackers to redirect or inject malicious code into the page that displayed the banner. This could compromise sensitive data or user sessions on the original page.

Technical details

The vulnerability is a window.opener exposure flaw (CWE-601, CWE-79) affecting smartbanner.js versions prior to 1.14.1. When the library opens external links via target="_blank", it omitted the rel="noopener" attribute, exposing the window.opener reference to the opened third-party page. An attacker controlling a third-party page linked via the banner can exploit this to redirect the original window or inject JavaScript, affecting users on desktop browsers and older mobile browsers lacking built-in noopener protection. The patch automatically adds rel="noopener" to all links. No evidence of exploitation in the wild has been reported.

Affected products

  • smartbanner.js smartbanner.js before 1.14.1

Timeline

  • 2019-09-13: disclosed
  • 2019-09-11: patched: Fix released in version 1.14.1

References