Reflected cross-site scripting (XSS) In mustache
Description
Cross-Site Scripting in mustache
Versions of mustache prior to 2.2.1 are affected by a cross-site scripting vulnerability when attributes in mustache templates are not quoted.
Example
Template:
<a href={{foo}}/>
Input:
{ 'foo' : 'test.com onload=alert(1)'}
Rendered result:
<a href=test.com onload=alert(1)/>
Recommendation
Update to version 2.2.1 or later. Alternatively, ensure that all attributes in hmustache templates are encapsulated with quotes.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
debian 13 | - | ||
npm | 2.2.1 | ||
debian 14 | - | ||
debian 12 | - |
Aliases
1. 2. 3. 4. 5. 6. 7.
References
1. 2. 3. 4.