Executive brief
Eco is a template engine for embedding CoffeeScript in HTML. The default HTML escape function fails to escape single quotes, allowing attackers to inject malicious JavaScript code that executes in users' browsers when rendering templated content. This can lead to session hijacking, credential theft, or malware distribution.
Technical details
Eco is vulnerable to Cross-Site Scripting (CWE-79) because its default __escape implementation does not escape single quotes in user input. An attacker can inject a payload like x'onmouseover='alert(document.domain) into a template variable, and when rendered in a single-quoted HTML attribute (e.g., value='<%= @value %>'), the single quote closes the attribute, allowing arbitrary event handler execution. The vulnerability affects all versions of eco. The attack vector is network-based and requires the attacker to control template data; no authentication or user interaction beyond normal browsing is required. At the time of advisory publication, no patch was available and the project was recommended to be replaced with an alternative.
Affected products
- eco eco all versions
Timeline
- 2020-09-03: disclosed