The @apostrophecms/seo package injects the Google Analytics Tracking ID (seoGoogleTrackingId) and Google Tag Manager ID (seoGoogleTagManager) directly into <script> tag bodies using JavaScript template literals without any sanitization or validation.
Any user with editor-level access (the default role for content managers) can set these fields to a malicious value, resulting in stored XSS that executes on every page for every visitor of the site.
The vulnerable code is in node_modules/@apostrophecms/seo/lib/nodes.js.
Google Analytics (lines 218–224):
// seoGoogleTrackingId is inserted RAW into a <script> body — no escaping, no validation
body: [ {
raw: `
window.dataLayer = window.dataLayer || [];
function gtag(){dataLayer.push(arguments);}
gtag('js', new Date());
gtag('config', '${global.seoGoogleTrackingId}');
`
} ]
Google Tag Manager (lines 358–362):
body: [ {
raw: `(function(w,d,s,l,i){...})(window,document,'script','dataLayer','${global.seoGoogleTagManager}');`
} ]
These nodes are rendered by renderNodes() in ApostropheCMS core (modules/@apostrophecms/template/index.js lines 1176–1177):
if (node.raw != null) {
return node.raw; // returned verbatim, no escaping
}
The fields seoGoogleTrackingId and seoGoogleTagManager are defined as plain type: 'string' values with no pattern, minimum length, or maximum length validation in seo-fields-global/index.js lines 347–352.
ApostropheCMS's permission model (@apostrophecms/permission/index.js line 121) grants editor-level users the ability to edit and publish the global singleton, meaning a contributor does not need administrator...
1.5.0Exploitability
AV:NAC:LPR:LUI:RScope
S:CImpact
C:HI:HA:N8.7/CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:NInjection