URL Shortener by Rebrandly
eaidebojanpehpceonghnmgdofblnlae
Risk Score
4.71
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE-2021-23358 in bundled underscore@1.8.3 enables arbitrary code execution; not patched.
- importScripts loads remote Workbox CDN in service worker — remote code execution surface.
- new Function() constructor executes dynamic string code on window — high code quality risk.
- Privacy policy admits data collection and 3rd-party sharing but is not scoped to this extension.
- Content script declared on <all_urls> gives page-level access to every site visited.
Evidence
- critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE); fixed_in 1.12.1 — bundled version not patched.
- import_scripts_remote crx service-worker.js calls importScripts on https://storage.googleapis.com/workbox-cdn — remote code load.
- function_constructor crx new Function(T[P])(window) in chunk JS — dynamic code execution on window object.
- privacy_policy_broad store Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — v3.5 D applies → +10.
- content_script_all_urls manifest content_scripts_matches includes <all_urls>; extension runs on every page.
- verified_publisher_featured store Extension is verified publisher AND featured by Google; discount applied but capped by monetization/CVE rules.
- uninstall_url_hijack crx uninstall_url_target=https://rebrandly.live/Uninstall-Extension-Firefox — own domain, not 3rd party.
- werxltd_external_host crx js_external_hosts includes werxltd.com — third-party domain outside rebrandly namespace; warrants review.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- contextMenus low Used to add right-click shortcut; low standalone risk.
- identity medium OAuth token access; scoped but enables auth impersonation if abused.
- activeTab medium Access current tab URL/content on user action; limited to active tab.
- tabs medium Can read URLs of open tabs; moderate surveillance surface.
- storage low Local extension data storage; low risk in isolation.
- clipboardWrite low Copies shortened URL to clipboard; output-only, low risk.
- scripting medium Can inject scripts; combined with <all_urls> content_script raises risk.
- content_scripts:<all_urls> high Content script runs on every page via <all_urls> match; broad page access.
- host_permissions:*://*.rebrandly.com/* low Scoped to own domain; expected for URL shortener service.
- host_permissions:*://rebrandly.live/* low Secondary own domain; acceptable scope.
Pillar Scores
Permissions3.80
Reputation2.00
Network3.50
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality7.50
CVE Exposure7.00
Scoring History
| sssiedn320d0c72dp727562726963xsx | 5.07 | Medium | review | 2026-08-30 |
| fsssiedxa sssiedx | 4.57 | Medium | review | 2026-08-20 |
| sssieddrubricxsx | 4.46 | Medium | review | 2026-08-20 |
| v3.6 | 4.71 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:29
Listing SHA
6ddef1fbb3d2…
Force block
— not fired
Score recovered
no
Elapsed
35.5s