Executive brief
takeapeek is a popular npm package used for file preview functionality in web applications. The package fails to properly clean up filenames before displaying them, allowing an attacker to inject malicious JavaScript that runs in users' browsers when they preview crafted files. This could lead to account compromise, session hijacking, or theft of sensitive data from the user's session.
Technical details
The vulnerability is a reflected Cross-Site Scripting (CWE-79) flaw stemming from insufficient input validation and output encoding of filenames. The package displays filenames without sanitizing or HTML-encoding them, allowing an attacker to embed script tags or event handlers directly in filenames (e.g., "<img src=x onerror=alert('xss')>.txt"). When a victim previews the file using takeapeek, the malicious JavaScript executes in their browser context. The attack vector is network-based and requires user interaction (opening/previewing a file with a malicious name). As of the 2020 advisory, no patch was available and the package maintainers recommended switching to an alternative.
Affected products
- npm takeapeek all versions
Timeline
- 2020-09-03: disclosed: Advisory GHSA-4q2f-8g74-qm56 published on GitHub Advisory Database