Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

TickTick - Todo & Task List

diankknpkndanachmlckaikddgcehkod
Risk Score
4.47
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 200,000
Rating 4.2
Last updated 2026-05-26 (1 months ago)
Manifest version MV3
CSP present ✅ yes
Developer support@ticktick.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358: Arbitrary Code Execution); not updated to fixed version.
  • Privacy policy fetched but scope_extension==false AND data_collection+third_party_sharing==true — admits broad sharing without extension-specific scoping.
  • Three moderate XSS CVEs in jquery@1.9.1 combined with innerHTML DOM-XSS sink in contentscript.js running on all pages.
  • cookies + *://*/* host permission allows reading session cookies from any site visited.
  • new Function() constructor present in multiple content/background scripts alongside CVE-affected DOM-manipulation libraries.

Evidence

  • cve_critical_underscore crx underscore@1.8.3 carries CVE-2021-23358 (critical ACE); fixed_in 1.12.1 — bundled version far behind.
  • cve_jquery_xss crx jquery@1.9.1 carries 3 moderate XSS CVEs (CVE-2019-11358, CVE-2020-11023, CVE-2015-9251); fixed_in 3.4-3.5.
  • privacy_policy_scope_mismatch store Policy at ticktick.com/about/privacy fetched; scope_extension=false, data_collection=true, third_party_sharing=true.
  • dom_xss_sink_with_cve_libs crx innerHTML user-controlled sink in contentscript.js co-present with CVE-affected jquery; FIX B applies (+2.0 code).
  • broad_host_with_cookies manifest cookies permission + *://*/* host_permissions — can exfiltrate session cookies from any domain.
  • verified_publisher_featured store Verified publisher + Google Featured badge; reputation floor 2.0 applies.
  • function_constructor_multi_file crx new Function() constructor found in 5 JS files including background and content scripts.
  • no_developer_name store developer_name field is empty string; only email support@ticktick.com present.

CVE Exposures (5)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS
CVE-2019-11358 jquery@1.9.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11023 jquery@1.9.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@1.9.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • scripting medium Allows injecting JS into pages; paired with broad host_permissions elevates risk.
  • tabs medium Can read URL/title of all open tabs.
  • storage low Local data persistence; low inherent risk.
  • contextMenus low Adds right-click menu items; low risk.
  • cookies high Can read/write cookies. Paired with *://*/* host access this is high risk.
  • sidePanel low Opens a side panel UI; low inherent risk.
  • *://*/* high Broad host permission grants access to all sites; amplifies scripting and cookies risk.

Pillar Scores

Permissions5.50
Reputation2.00
Network2.00
Webstore1.00
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure8.50

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:27
Listing SHA 519069cb22f7…
Force block — not fired
Score recovered no
Elapsed 35.2s