Junglewise Threat Intelligence

sweetalert2 undesirable behavior on specific TLDs

Severity: info · Published 2023-07-10

Technologies: Sweetalert2. Vendors: npm.

Executive brief

sweetalert2 is a popular JavaScript library for displaying alert dialogs and notifications in web applications. Versions 11.6.14 to 11.22.3 contained code that played audio or video messages unrelated to the library's core functionality when users accessed websites from certain country-specific domain extensions. This "protestware" behavior could interrupt user experience and distract from the application's normal operations.

Technical details

The vulnerability (CWE-440: Unexpected Behavior) involves undesirable and undocumented code execution triggered by domain suffix matching. Specifically, the library would play audio/video messages unrelated to its alert dialog functionality when accessed from certain TLDs (.ru, .su, .рф). This behavior was triggered automatically on specific domains without user consent or clear application purpose, effectively injecting disruptive content into applications using the library. The issue affected versions 11.6.14 through 11.22.3 and was patched in 11.22.4 by removing the problematic code entirely.

Affected products

  • sweetalert2 sweetalert2 11.6.14 to before 11.22.4

Timeline

  • 2023-07-10: disclosed
  • 2025-08-14: patched

References

Related threats