TickTick - Todo & Task List
diankknpkndanachmlckaikddgcehkod
Risk Score
4.47
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358: Arbitrary Code Execution); not updated to fixed version.
- Privacy policy fetched but scope_extension==false AND data_collection+third_party_sharing==true — admits broad sharing without extension-specific scoping.
- Three moderate XSS CVEs in jquery@1.9.1 combined with innerHTML DOM-XSS sink in contentscript.js running on all pages.
- cookies + *://*/* host permission allows reading session cookies from any site visited.
- new Function() constructor present in multiple content/background scripts alongside CVE-affected DOM-manipulation libraries.
Evidence
- cve_critical_underscore crx underscore@1.8.3 carries CVE-2021-23358 (critical ACE); fixed_in 1.12.1 — bundled version far behind.
- cve_jquery_xss crx jquery@1.9.1 carries 3 moderate XSS CVEs (CVE-2019-11358, CVE-2020-11023, CVE-2015-9251); fixed_in 3.4-3.5.
- privacy_policy_scope_mismatch store Policy at ticktick.com/about/privacy fetched; scope_extension=false, data_collection=true, third_party_sharing=true.
- dom_xss_sink_with_cve_libs crx innerHTML user-controlled sink in contentscript.js co-present with CVE-affected jquery; FIX B applies (+2.0 code).
- broad_host_with_cookies manifest cookies permission + *://*/* host_permissions — can exfiltrate session cookies from any domain.
- verified_publisher_featured store Verified publisher + Google Featured badge; reputation floor 2.0 applies.
- function_constructor_multi_file crx new Function() constructor found in 5 JS files including background and content scripts.
- no_developer_name store developer_name field is empty string; only email support@ticktick.com present.
CVE Exposures (5)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
| CVE-2019-11358 | jquery@1.9.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.9.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.9.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
Permissions Breakdown
- scripting medium Allows injecting JS into pages; paired with broad host_permissions elevates risk.
- tabs medium Can read URL/title of all open tabs.
- storage low Local data persistence; low inherent risk.
- contextMenus low Adds right-click menu items; low risk.
- cookies high Can read/write cookies. Paired with *://*/* host access this is high risk.
- sidePanel low Opens a side panel UI; low inherent risk.
- *://*/* high Broad host permission grants access to all sites; amplifies scripting and cookies risk.
Pillar Scores
Permissions5.50
Reputation2.00
Network2.00
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure8.50
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:27
Listing SHA
519069cb22f7…
Force block
— not fired
Score recovered
no
Elapsed
35.2s