Advisories for Golang/Github.com/Ewen-Lbh/Ffcss package

2023

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

ffcss is a CLI interface to apply and configure Firefox CSS themes. Prior to 0.2.0, the function lookupPreprocess() is meant to apply some transformations to a string by disabling characters in the regex [-_ .]. However, due to the use of late Unicode normalization of type NFKD, it is possible to bypass that validation and re-introduce all the characters in the regex [-_ .]. The lookupPreprocess() can be easily bypassed …