GHSA-4233-7q5q-m7p6
google-translate-api-browser Server-Side Request Forgery (SSRF) Vulnerability
Quick fix
GHSA-4233-7q5q-m7p6 — google-translate-api-browser: upgrade to the fixed version with the command below.
npm install google-translate-api-browser@4.1.0Details
### Summary A Server-Side Request Forgery (SSRF) Vulnerability is present in applications utilizing the `google-translate-api-browser` package and exposing the `translateOptions` to the end user. An attacker can set a malicious `tld`, causing the application to return unsafe URLs pointing towards local resources.
### Details The `translateOptions.tld` field is not properly sanitized before being placed in the Google translate URL. This can allow an attacker with control over the `translateOptions` to set the `tld` to a payload such as `@127.0.0.1`. This causes the full URL to become `https://translate.google.@127.0.0.1/...`, where `translate.google.` is the username used to connect to localhost.
### PoC Imagine a server running the following code (closely mimicking the code present in the package's README): ```javascript const express = require('express'); const { generateRequestUrl, normaliseResponse } = require('google-translate-api-browser'); const https = require('https');
const app = express(); app.use(express.json());
app.post('/translate', async (req, res) => { const { text, options } = req.body;
const url = generateRequestUrl(text, options);
https.get(url, (resp) => { let data = ''; resp.on('data', (chunk) => { data += chunk; }); resp.on('end', () => { res.json(normaliseResponse(JSON.parse(data))); }); }).on("error", (err) => { console.log("Error: " + err.message); }); });
const port = 3000; app.listen(port, () => { console.log(`Server is running on port ${port}`); }); ```
An attacker can then send the following POST request to `/translate`: ``` POST /translate HTTP/1.1 Host: localhost:3000 Content-Type: application/json Content-Length: 51
{"text":"Hello","options": {"tld": "@127.0.0.1"} } ```
This will cause a request to be sent to the localhost of the server running the Node application.
### Impact An attacker can send requests within internal networks and the local host. Should any HTTPS application be present on the internal network with a vulnerability exploitable via a GET call, then it would be possible to exploit this using this vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 4.1.0npm install google-translate-api-browser@4.1.0References
- https://github.com/cjvnjde/google-translate-api-browser/security/advisories/GHSA-4233-7q5q-m7p6[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-48711[ADVISORY]
- https://github.com/cjvnjde/google-translate-api-browser/commit/33c2eac4a21c6504409e7b06dd16e6346f93d34b[WEB]
- https://github.com/cjvnjde/google-translate-api-browser[PACKAGE]