AuthoredUp – No. 1 LinkedIn ™ Content Tool
dkkmpkpjimkollpfgbbglcikcmgmdlhn
Risk Score
4.08
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE-2021-23358 in bundled underscore@1.8.3 enables arbitrary code execution; not patched to 1.12.1+.
- Privacy policy fetched but scope_extension=false and admits data_collection+third_party_sharing — D rule triggers +10.0.
- brand_mention.is_impersonation=true for LinkedIn without verified publisher — +2.0 reputation hit.
- new Function() constructor found in guest and background scripts — code quality risk with no CSP present.
- MV3 with no CSP: underscore CVE (DOM-manipulation lib) triggers ×1.5 CVE amplifier, pushing CVE pillar to 7.0.
Evidence
- critical_cve_bundled_lib crx underscore@1.8.3 bundles CVE-2021-23358 (critical ACE); fixed_in 1.12.1 — library not upgraded.
- high_cve_bundled_lib crx underscore@1.8.3 bundles CVE-2026-27601 (high DoS via recursion); fixed_in 1.13.8.
- no_csp manifest content_security_policy is null; no CSP defined — ×1.5 CVE amplifier applies.
- privacy_policy_generic_admits_sharing store Policy fetched but scope_extension=false, data_collection=true, third_party_sharing=true → Privacy pillar +10.0.
- brand_impersonation store brand_mention.is_impersonation=true for LinkedIn; developer not verified_publisher nor featured by Google on impersonation check.
- function_constructor crx new Function() constructor present in guest_script.js and background_script.js — dynamic code construction risk.
- is_featured_by_google store Extension carries Google Featured badge — partial trust signal, applied -2.0 reputation discount.
- host_permission_linkedin_only manifest Host access scoped to *.linkedin.com only; justified for LinkedIn content tool — no broad host access.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- storage low Local key-value store; no cross-site or exfil risk on its own.
- *://*.linkedin.com/* medium Host permission scoped narrowly to linkedin.com; enables content-script injection on that domain.
Pillar Scores
Permissions2.00
Reputation5.50
Network2.00
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-15 14:07
Listing SHA
eb8ce9dbb832…
Force block
— not fired
Score recovered
no
Elapsed
25.9s