{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/ssr/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@vue/server-renderer (\u003c= 3.5.41)"],"_cs_severities":["high"],"_cs_tags":["xss","web-application","vue","ssr","code-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Vue"],"content_html":"\u003cp\u003eThe \u003ccode\u003e@vue/server-renderer\u003c/code\u003e package (version 3.5.41 and earlier) contains a vulnerability in its server-side rendering (SSR) logic that permits stored Cross-Site Scripting (XSS). The function \u003ccode\u003essrRenderDynamicAttr\u003c/code\u003e, which handles dynamic attributes bound via \u003ccode\u003ev-bind\u003c/code\u003e, relies on an attribute name validation utility (\u003ccode\u003eisSSRSafeAttrName\u003c/code\u003e) to sanitize keys. This utility utilizes a blacklist that fails to include the carriage return character (U+000D).\u003c/p\u003e\n\u003cp\u003eBecause web browsers perform HTML input stream preprocessing - converting carriage returns not followed by line feeds into line feeds - an attacker who can influence the keys in a bound object can supply a string containing \u003ccode\u003e\\r\u003c/code\u003e. This character terminates the intended attribute name and allows for the injection of new, arbitrary attributes (e.g., \u003ccode\u003eautofocus\u003c/code\u003e or \u003ccode\u003eonfocus\u003c/code\u003e) into the rendered HTML output. Since this occurs during the server-side rendering phase, the resulting XSS payload is served directly to users, leading to full script execution in the context of the victim's session without requiring user interaction.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a feature in a web application that renders user-controllable object keys using Vue SSR (e.g., dynamic attribute configuration in a CMS or form builder).\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious input string containing carriage returns (e.g., \u003ccode\u003ex\\rautofocus\\ronfocus\u003c/code\u003e) to be used as a key in a dynamic attribute object.\u003c/li\u003e\n\u003cli\u003eThe application passes the malicious object to \u003ccode\u003ev-bind\u003c/code\u003e or the internal \u003ccode\u003essrRenderAttrs()\u003c/code\u003e function during server-side rendering.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eisSSRSafeAttrName\u003c/code\u003e utility validates the key against its blacklist; since \u003ccode\u003e\\r\u003c/code\u003e is not blocked, it marks the key as safe.\u003c/li\u003e\n\u003cli\u003eThe server-side code generates an HTML string where the \u003ccode\u003e\\r\u003c/code\u003e remains embedded in the attribute name (e.g., \u003ccode\u003e\u0026lt;div x\\rautofocus\\ronfocus=\u0026quot;...\u0026quot;\u0026gt;\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe server sends this generated HTML to the victim's browser.\u003c/li\u003e\n\u003cli\u003eThe browser performs HTML input stream normalization, interpreting the \u003ccode\u003e\\r\u003c/code\u003e characters as delimiters, effectively creating new attributes like \u003ccode\u003eautofocus\u003c/code\u003e and \u003ccode\u003eonfocus\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe browser executes the injected JavaScript code (e.g., \u003ccode\u003ealert(document.cookie)\u003c/code\u003e) upon page load.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full stored XSS within the target application. This allows attackers to execute arbitrary JavaScript in the context of any user viewing the affected page, leading to session hijacking, unauthorized data exfiltration, and potential complete account takeover. The vulnerability is highly severe in SSR contexts where dynamic object binding is used to construct HTML elements from untrusted inputs, such as in administrative dashboards or user-facing portals supporting custom configurations.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the following actions for your development and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade \u003ccode\u003e@vue/server-renderer\u003c/code\u003e to a patched version that explicitly blacklists carriage return (U+000D) characters in \u003ccode\u003eisSSRSafeAttrName\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003ePerform a code audit of all SSR-enabled Vue components to identify instances where \u003ccode\u003ev-bind\u003c/code\u003e or \u003ccode\u003essrRenderAttrs\u003c/code\u003e processes objects with keys derived from external data.\u003c/li\u003e\n\u003cli\u003eImplement strict allowlists for dynamic attribute names where user input is involved, rather than relying solely on blacklisting unsafe characters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-06T00:46:42Z","date_published":"2026-10-06T00:46:42Z","id":"https://feed.craftedsignal.io/briefs/2026-10-vue-ssr-xss/","summary":"An insufficient character blacklist in @vue/server-renderer allows attackers to inject arbitrary HTML attributes by including carriage return characters in dynamic binding keys.","title":"Stored XSS in @vue/server-renderer via Attribute Name Injection","url":"https://feed.craftedsignal.io/briefs/2026-10-vue-ssr-xss/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:devalue_project:devalue:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-92708"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["devalue (5.1.0 - 5.9.2)"],"_cs_severities":["high"],"_cs_tags":["information-disclosure","supply-chain","npm","ssr"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe 'devalue' npm package (versions 5.1.0 through 5.9.2) contains an information disclosure vulnerability, identified as CVE-2026-92708, resulting from incorrect serialization of Node.js Buffer objects. When using the 'stringify' or 'uneval' functions, the library serializes the underlying process-wide memory backing the Buffer rather than the specific view intended.\u003c/p\u003e\n\u003cp\u003eBecause Node.js utilizes a shared pool for Buffer memory, this vulnerability allows for the leakage of up to 64 KB of unrelated process memory into serialized output. In the context of Server-Side Rendering (SSR) frameworks such as SvelteKit or Nuxt, this behavior can be exploited by an unauthenticated party to extract sensitive data belonging to other users. This includes bytes from concurrent requests, such as HTTP request bodies or Authorization headers, which are subsequently embedded into server-rendered HTML. Unlike other vulnerabilities in the library, this issue occurs during serialization and is not mitigated by existing prototype pollution or Denial of Service guards, potentially impacting every SSR render involving Buffer objects.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a severe risk of data exfiltration in web applications utilizing 'devalue' for server-side state serialization. By repeatedly triggering server-side renders that include small Buffers, an attacker can harvest sensitive data from the application's process memory. This exposure includes authentication tokens, user-specific request data, and other sensitive information from concurrent traffic. Successful exploitation leads to unauthorized data access and potential account takeover or business logic compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize remediation for all applications using 'devalue' for SSR state handling.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to a version of 'devalue' that addresses the memory serialization behavior.\u003c/li\u003e\n\u003cli\u003eIf an immediate upgrade is unavailable, manually convert all Node.js Buffer objects to Uint8Array instances before passing them to 'devalue.stringify()' or 'devalue.uneval()' as a temporary mitigation.\u003c/li\u003e\n\u003cli\u003eAudit SSR logic in SvelteKit and Nuxt applications to identify instances where Buffer objects are included in serialized state.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T20:22:24Z","date_published":"2026-10-01T20:22:24Z","id":"https://feed.craftedsignal.io/briefs/2026-10-devalue-memory-leak/","summary":"The devalue library improperly serializes Node.js Buffer objects, exposing up to 64 KB of process-wide memory to end users in SSR environments via CVE-2026-92708.","title":"Information Disclosure via Improper Buffer Serialization in devalue","url":"https://feed.craftedsignal.io/briefs/2026-10-devalue-memory-leak/"}],"language":"en","title":"CraftedSignal Threat Feed - Ssr","version":"https://jsonfeed.org/version/1.1"}