Junglewise Threat Intelligence

mustache.js XSS via unquoted template attributes

Severity: info · CVSS 6.1 · Published 2018-10-09

Vendors: npm.

Executive brief

Mustache is a popular logic-less template engine used to generate web pages and other text formats. A vulnerability in versions prior to 2.2.1 allows attackers to inject malicious scripts into web pages viewed by users. This could lead to unauthorized actions being performed in a user's browser, such as stealing session cookies or redirecting users to fraudulent websites.

Technical details

A cross-site scripting (XSS) vulnerability exists in the mustache package for Node.js in versions prior to 2.2.1. The issue stems from improper neutralization of input during web page generation when a template utilizes an attribute that is not enclosed in quotes. A remote attacker can exploit this by providing crafted input that breaks out of the intended attribute context, allowing for the execution of arbitrary JavaScript in the victim's browser. This requires the victim to interact with a page rendered using a vulnerable template. The vulnerability is addressed in version 2.2.1.

Affected products

  • mustache.js project mustache < 2.2.1

Timeline

  • 2017-01-23: advisory: NVD published CVE-2015-8862
  • 2018-10-09: advisory: GitHub Advisory GHSA-3233-rgx3-c2wh published
  • 2020-06-16: other: GitHub Advisory withdrawn as a duplicate publish

Related threats