Executive brief
Knockout is a popular JavaScript library used to build interactive web applications. An XSS vulnerability exists in how it binds the HTML "name" attribute on older Internet Explorer browsers (IE7 and earlier), allowing attackers to inject arbitrary JavaScript code if they can control the value bound to a name attribute. This could lead to session hijacking, credential theft, or malware distribution to affected users.
Technical details
The vulnerability exists in the setElementName utility function in Knockout, which uses string concatenation to build a DOM element when applying IE 6/7 workarounds for the name attribute. Specifically, the value is directly concatenated into an HTML string passed to mergeAttributes without proper escaping: element.mergeAttributes(document.createElement("<input name='" + element.name + "'/>"), false). An attacker who can control the value bound to the name attribute can inject malicious HTML/JavaScript. The vulnerability affects Knockout versions before 3.5.0, where the fix properly escapes special characters. This only impacts older Internet Explorer browsers (IE7 and below) due to the IE-specific code path involved.
Affected products
- Knockout Knockout before 3.5.0
Timeline
- 2021-02-25: disclosed
- 3.5.0: patched