Just in:
Anthropic reopens Mythos 5 for cyber defenders // Beijing widens Japan curbs as Takaichi row deepens // CG Capital, the Leader in Branded Residences in Thailand, Marks Milestone Success for InterContinental Residences Bangkok Asoke Amid Global Economic Uncertainty // Bid To Rebuild Bengal To Its Old Glory Is Welcome, Though Difficult // Oil gains as Gulf truce faces strain // OpenAI limits Sol launch amid cyber risks // Save the Children Hong Kong’s Play to Thrive: Prioritising Personal Growth Over Competitive Success // Masdar starts Kazakh wind power push // PlayStation sales hit May low // Construction Management Awards 2026 – Now open for nomination Introduction of the Inaugural “Excellent Construction Safety Culture Award” Guides the Construction Industry Toward a New Milestone in Safety // Afogreen Build Highlights Growing Adoption of Building Performance Modelling in Australia’s Sustainability-Driven Construction Sector // This summer will never stop us from our wellness routine // Bracell Welcomes Fernando Branco’s Appointment to Lead ABAF and Reinforces Commitment to Sustainable Forestry Development in Bahia // XRG and Eni deepen Argentina LNG push // Abu Dhabi starts new Saadiyat arts landmark // France and Oman press toll-free Hormuz passage // Cheap RAT spreads through Telegram channels // PRHK 2026 Benchmark Report highlights how Hong Kong’s IPO revival, AI, and the GBA are reshaping the SAR’s PR industry // Tehran blocks French role in Hormuz clearance // Hawaii tests plastic waste in roads //

An insecure mess: How flawed JavaScript is turning web into a hacker's playground

javascriptistock

northeasternjavascriptlibraries.png

This chart shows the fraction of JavaScript library versions with distinct known vulnerabilities, each represented by colors, out of the total library versions in brackets.


Image: Northeastern University

An analysis of over 133,000 websites has found that 37 percent of them have at least one JavaScript library with a known vulnerability.

Researchers from Northeastern University have followed up on research in 2014 that drew attention to potential security risks caused by loading outdated versions of JavaScript libraries, such as such as jQuery, and the AngularJS framework in the browser.

ADVERTISEMENT

As the Northeastern researchers highlight in a new paper, vulnerable libraries can be dangerous under the right conditions, pointing to an old cross-site scripting bug in jQuery, which will allow an attacker to inject malicious scripts into a vulnerable site.

They looked at domains from Amazon’s Alexa Top 75,000 list and 75,000 randomly selected .com domains, assessing 72 different libraries and their respective versions. Overall, 87 percent of the Alexa sites and 46.5 percent of the .com sites use one of the 72 libraries.

The study found that “36.7 percent of jQuery, 40.1 percent of Angular, 86.6 percent of Handlebars, and 87.3 percent of YUI inclusions use a vulnerable version.” Additionally, 9.7 percent of the sites in the study use two or more vulnerable library versions.

However, the most popular sites in the study were found to be far less likely to include a vulnerable library. The researchers found that only 21 percent of the top 100 Alexa sites did so.

Still, the researcher’s overall take on the state of security for the JavaScript ecosystem is that it’s a complete mess.

“Perhaps our most sobering finding is practical evidence that the JavaScript library ecosystem is complex, unorganised, and quite ‘ad hoc’ with respect to security,” the researchers write.

“There are no reliable vulnerability databases, no security mailing lists maintained by library vendors, few or no details on security issues in release notes, and often, it is difficult to determine which versions of a library are affected by a specific reported vulnerability.”

Remediation won’t be a simple task either because the vast majority of sites use libraries that are so far out of date. For example, the median lag between the oldest version on each website and the newest version is over three years.

“We observe that only very small fraction of potentially vulnerable sites — 2.8 percent in Alexa, 1.6 percent in .com — could become free of vulnerabilities by applying patch-level updates, ie, an update of the least significant version component, such as from 1.2.3 to 1.2.4, which would generally be expected to be backwards compatible,” the researchers note.

“The vast majority of sites would need to install at least one library with a more recent major or minor version, which might necessitate additional code changes due to incompatibilities.”

More on security

(via PCMag)



Notice an issue?

Arabian Post strives to deliver the most accurate and reliable information to its readers. If you believe you have identified an error or inconsistency in this article, please don't hesitate to contact our editorial team at editor[at]thearabianpost[dot]com. We are committed to promptly addressing any concerns and ensuring the highest level of journalistic integrity.


ADVERTISEMENT
Social Media Auto Publish Powered By : XYZScripts.com
Just in: