Executive brief
Unhead is a package that manages HTML head tags for web frameworks. A vulnerability in its safety sanitizer allows attackers to bypass protections against malicious links by using different letter casings (e.g., "DATA:" instead of "data:"). This can lead to injection of malicious CSS or JavaScript that affects page rendering or steals user data, though actual impact is limited by the lack of direct execution privileges.
Technical details
The vulnerability is a case-sensitivity bypass in the makeTagSafe function (safe.ts, lines 68-71), which uses String.includes() to block 'javascript:' and 'data:' URI schemes in href attributes. Since JavaScript's includes() method is case-sensitive but browsers parse URI schemes case-insensitively, an attacker can bypass the filter using alternate casings like 'DATA:', 'JAVASCRIPT:', or 'dAtA:'. An attacker providing untrusted input to useHeadSafe() can inject arbitrary CSS (via data: URIs) for UI redressing or attribute selector-based exfiltration. The fix involves converting the href value to lowercase before performing the scheme check. The vulnerability was patched in version 2.1.11; affected versions are ≤2.1.10.
Affected products
- unjs unhead <=2.1.10
Timeline
- 2026-03-12: disclosed
- 2026-03-12: patched: Fixed in version 2.1.11