VDB
Sign up
—0.0

GHSA-5339-hvwr-7582

Unhead Vulnerable to Bypass of URI Scheme Sanitization in makeTagSafe via Case-Sensitivity

Quick fix

GHSA-5339-hvwr-7582 — unhead: upgrade to the fixed version with the command below.

npm install unhead@2.1.11

Details

The `link.href` check in `makeTagSafe` (safe.ts, line 68-71) uses `String.includes()`, which is case-sensitive:

```typescript if (key === 'href') { if (val.includes('javascript:') || val.includes('data:')) { return } next[key] = val } ```

Browsers treat URI schemes case-insensitively. `DATA:text/css,...` is the same as `data:text/css,...` to the browser, but `'DATA:...'.includes('data:')` returns `false`.

### PoC

```javascript useHeadSafe({ link: [{ rel: 'stylesheet', href: 'DATA:text/css,body{display:none}' }] }) ```

SSR output:

```html <link rel="stylesheet" href="DATA:text/css,body{display:none}"> ```

The browser loads this as a CSS stylesheet. An attacker can inject arbitrary CSS for UI redressing or data exfiltration via CSS attribute selectors with background-image callbacks.

Any case variation works: `DATA:`, `Data:`, `dAtA:`, `JAVASCRIPT:`, etc.

## Suggested fix

```typescript if (key === 'href') { const lower = val.toLowerCase() if (lower.includes('javascript:') || lower.includes('data:')) { return } next[key] = val } ```

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/unhead
Introduced in: 0Fixed in: 2.1.11
Fixnpm install unhead@2.1.11

References