VDB
Sign up
MEDIUM6.3

GHSA-2rwj-7xq8-4gx4

Qwik has a potential mXSS vulnerability due to improper HTML escaping

Quick fix

GHSA-2rwj-7xq8-4gx4 — @builder.io/qwik: upgrade to the fixed version with the command below.

npm install @builder.io/qwik@1.7.3

Details

### Summary

A potential mXSS vulnerability exists in Qwik for versions up to 1.6.0.

### Details

Qwik improperly escapes HTML on server-side rendering. It converts strings according to the following rules:

https://github.com/QwikDev/qwik/blob/v1.5.5/packages/qwik/src/core/render/ssr/render-ssr.ts#L1182-L1208

- If the string is an attribute value: - `"` -> `&quot;` - `&` -> `&amp;` - Other characters -> No conversion - Otherwise: - `<` -> `&lt;` - `>` -> `&gt;` - `&` -> `&amp;` - Other characters -> No conversion

It sometimes causes the situation that the final DOM tree rendered on browsers is different from what Qwik expects on server-side rendering. This may be leveraged to perform XSS attacks, and a type of the XSS is known as mXSS (mutation XSS).

## PoC

A vulnerable component: ```javascript import { component$ } from "@builder.io/qwik"; import { useLocation } from "@builder.io/qwik-city";

export default component$(() => { // user input const { url } = useLocation(); const href = url.searchParams.get("href") ?? "https://example.com";

return ( <div> <noscript> <a href={href}>test</a> </noscript> </div> ); }); ```

If a user accesses the following URL, ``` http://localhost:4173/?href=</noscript><script>alert(123)</script> ``` then, `alert(123)` will be executed.

### Impact

XSS

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@builder.io/qwik
Introduced in: 0Fixed in: 1.7.3
Fixnpm install @builder.io/qwik@1.7.3

References