Junglewise Threat Intelligence

diagram-js-direct-editing cross-site scripting via clipboard

Severity: info · Published 2020-09-11

Vendors: npm.

Executive brief

diagram-js-direct-editing is a JavaScript library that provides inline editing support for diagram-js, a web-based diagram editor. The library fails to sanitize clipboard input, allowing attackers to inject malicious JavaScript code that executes in a victim's browser when pasting data into the editor. This could lead to theft of session tokens, keylogging, or other client-side attacks.

Technical details

The vulnerability is a Cross-Site Scripting (CWE-79) flaw in versions prior to 1.4.3. The direct-editing component does not properly sanitize or escape user input originating from the clipboard, allowing arbitrary HTML/JavaScript to be pasted and executed in the victim's browser context. The attack vector is local user interaction (pasting from clipboard), with no authentication required. An attacker can achieve arbitrary JavaScript execution within the browser context, potentially compromising user data or session integrity. The fix is available in version 1.4.3 and later.

Affected products

  • bpmn-io diagram-js-direct-editing before 1.4.3

Timeline

  • 2020-09-11: disclosed
  • 2020-09-11: patched: Fix released in version 1.4.3

References