Junglewise Threat Intelligence

eco Cross-Site Scripting via unescaped single quotes

Severity: info · Published 2020-09-03

Vendors: npm.

Executive brief

Eco is a template engine for embedding CoffeeScript in HTML. The default HTML escape function fails to escape single quotes, allowing attackers to inject malicious JavaScript code that executes in users' browsers when rendering templated content. This can lead to session hijacking, credential theft, or malware distribution.

Technical details

Eco is vulnerable to Cross-Site Scripting (CWE-79) because its default __escape implementation does not escape single quotes in user input. An attacker can inject a payload like x'onmouseover='alert(document.domain) into a template variable, and when rendered in a single-quoted HTML attribute (e.g., value='<%= @value %>'), the single quote closes the attribute, allowing arbitrary event handler execution. The vulnerability affects all versions of eco. The attack vector is network-based and requires the attacker to control template data; no authentication or user interaction beyond normal browsing is required. At the time of advisory publication, no patch was available and the project was recommended to be replaced with an alternative.

Affected products

  • eco eco all versions

Timeline

  • 2020-09-03: disclosed

References