Junglewise Threat Intelligence

Vercel serve-handler XSS in directory listing

Severity: info · Published 2021-02-23

Vendors: Vercel, npm.

Executive brief

serve-handler is a Node.js utility that serves files and directories over HTTP. It was vulnerable to HTML tag injection in the directory listing page, allowing an attacker to inject malicious script tags that execute in a visitor's browser when viewing a directory listing with a specially crafted name.

Technical details

The vulnerability was a reflected XSS (Cross-Site Scripting) caused by improper HTML escaping of template variables in the directory listing template file (directory.jst). An attacker could craft a directory name containing HTML or JavaScript tags, which would be inserted unsanitized into the page title and other template output. The attack requires a directory with a malicious name to exist on the server and for a user to visit that directory listing page. The fix, released in version 5.0.3, properly escapes template variables to prevent HTML/script injection.

Affected products

  • Vercel serve-handler before 5.0.3

Timeline

  • 2021-02-23: disclosed
  • 2021-02-23: patched: Fixed in version 5.0.3

References