Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

GoCashBack: Deals, Rebates, Savings Extension

edkmbojkflfanganifkkajmldejmhlec
Risk Score
5.49
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category Shopping
Installs 4,000
Rating 4.2
Last updated 2026-07-23 (1 months ago)
Manifest version MV3
CSP present ❌ no
Developer lonny.xue@55haitao.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE in bundled underscore@1.8.3 (arbitrary code execution) + high CVE + 2 moderate jQuery CVEs — no CSP amplifies XSS risk.
  • Broad host_permissions + cookies + webRequest on all sites: full traffic interception and cookie exfil possible.
  • Privacy policy admits data collection and third-party sharing but is not scoped to this extension.
  • Uninstall URL hijack detected; extension redirects on uninstall to a third-party URL.
  • No CSP defined (MV3 default): DOM-manipulation libs with known XSS CVEs operate without policy guard.

Evidence

  • cve_critical_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, arbitrary code execution); fixed in 1.12.1.
  • cve_high_underscore crx underscore@1.8.3 has CVE-2026-27601 (high, DoS via unlimited recursion); fixed in 1.13.8.
  • cve_moderate_jquery crx jquery@3.4.1 has CVE-2020-11022 and CVE-2020-11023 (moderate XSS); fixed in 3.5.0.
  • no_csp manifest content_security_policy is null; no CSP guard while bundling DOM-manipulation libs with active XSS CVEs.
  • uninstall_url_hijack crx chrome.runtime.setUninstallURL() set to third-party target on uninstall.
  • privacy_policy_unscoped store Policy fetched but scope_extension=false; admits data_collection=true and third_party_sharing=true — v3.5(D) applies.
  • broad_host_cookies_webrequest manifest cookies + webRequest + http://*/* + https://*/* = full cross-site traffic and cookie interception.
  • function_constructor crx new Function() found in all 3 JS bundles (content, background, popup); dynamic code construction risk.

CVE Exposures (4)

CVELibrarySeverity Fixed inSummary
CVE-2020-11022 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • cookies high Can read/write all cookies across all sites via broad host_permissions — affiliate tracking risk.
  • storage low Local extension storage only; low standalone risk.
  • tabs medium Can read tab URLs and titles; combined with broad host access raises surveillance risk.
  • webRequest high Intercepts all HTTP/S requests across all sites; high capability for traffic inspection.
  • http://*/* high Broad host permission covering all HTTP sites; enables content script injection everywhere.
  • https://*/* high Broad host permission covering all HTTPS sites; enables content script injection everywhere.

Pillar Scores

Permissions7.50
Reputation2.00
Network4.50
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure9.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 09:53
Listing SHA b3ca694d78d6…
Force block — not fired
Score recovered no
Elapsed