Summary
A Stored Cross-Site Scripting (XSS) vulnerability exists in the BlockNote editor component. Due to a lack of protocol validation in the FileBlock component and insufficient server-side inspection of block content, an attacker can inject a javascript: URI into the url property of a file block. This allows the execution of arbitrary JavaScript when a user clicks on the malicious file attachment.
Details
validateBlocknoteFieldOrThrow() only ensures that the incoming data is a valid JSON array. It does not inspect the internal properties of the blocks, specifically failing to validate the props.url field within blocks of type file.
- In FileBlock.tsx (line 103), the
block.props.url value is passed directly to the href attribute of an <a> tag without verifying the protocol (e.g., ensuring it starts with http://, https://, or mailto:).
PoC
To reproduce the issue, an attacker can send a createNote mutation with a manipulated blocknote JSON payload. The core of the payload involves a block of type file with a malicious URL:
{
"type": "file",
"props": {
"url": "javascript:void(alert(document.cookie))",
"name": "POC.pdf",
"fileCategory": "OTHER"
}
}
When the editor renders this block, it generates a link similar to:
<a href="javascript:void(alert(document.cookie))">POC.pdf</a>
Impact
An authenticated attacker can target any user (including admins) who has access to the compromised note. Arbitrary JavaScript execution can lead to session hijacking, sensitive data theft (via localStorage or cookies), or unauthorized actions performed on behalf of the victim.
Summary
A Stored Cross-Site Scripting (XSS) vulnerability exists in the BlockNote editor component. Due to a lack of protocol validation in the FileBlock component and insufficient server-side inspection of block content, an attacker can inject a javascript: URI into the url property of a file block. This allows the execution of arbitrary JavaScript when a user clicks on the malicious file attachment.
Details
validateBlocknoteFieldOrThrow()only ensures that the incoming data is a valid JSON array. It does not inspect the internal properties of the blocks, specifically failing to validate theprops.urlfield within blocks of type file.block.props.urlvalue is passed directly to the href attribute of an<a>tag without verifying the protocol (e.g., ensuring it starts with http://, https://, or mailto:).PoC
To reproduce the issue, an attacker can send a createNote mutation with a manipulated blocknote JSON payload. The core of the payload involves a block of type file with a malicious URL:
When the editor renders this block, it generates a link similar to:
<a href="javascript:void(alert(document.cookie))">POC.pdf</a>Impact
An authenticated attacker can target any user (including admins) who has access to the compromised note. Arbitrary JavaScript execution can lead to session hijacking, sensitive data theft (via localStorage or cookies), or unauthorized actions performed on behalf of the victim.