VDB
Sign up
MEDIUM6.1

GHSA-x77j-w7wf-fjmw

Nunjucks autoescape bypass leads to cross site scripting

Quick fix

GHSA-x77j-w7wf-fjmw — nunjucks: upgrade to the fixed version with the command below.

npm install nunjucks@3.2.4

Details

### Impact In Nunjucks versions prior to version 3.2.4, it was possible to bypass the restrictions which are provided by the autoescape functionality. If there are two user-controlled parameters on the same line used in the views, it was possible to inject cross site scripting payloads using the backslash `\` character.

#### Example If the user-controlled parameters were used in the views similar to the following: ``` <script> let testObject = { lang: '{{ lang }}', place: '{{ place }}' }; </script> ```

It is possible to inject XSS payload using the below parameters: ``` https://<application-url>/?lang=jp\&place=};alert(document.domain)// ```

### Patches The issue was patched in version 3.2.4.

### References

- https://bugzilla.mozilla.org/show_bug.cgi?id=1825980

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/nunjucks
Introduced in: 0Fixed in: 3.2.4
Fixnpm install nunjucks@3.2.4

References