GoCashBack: Deals, Rebates, Savings Extension
edkmbojkflfanganifkkajmldejmhlec
Risk Score
5.49
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Critical CVE in bundled underscore@1.8.3 (arbitrary code execution) + high CVE + 2 moderate jQuery CVEs — no CSP amplifies XSS risk.
- Broad host_permissions + cookies + webRequest on all sites: full traffic interception and cookie exfil possible.
- Privacy policy admits data collection and third-party sharing but is not scoped to this extension.
- Uninstall URL hijack detected; extension redirects on uninstall to a third-party URL.
- No CSP defined (MV3 default): DOM-manipulation libs with known XSS CVEs operate without policy guard.
Evidence
- cve_critical_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, arbitrary code execution); fixed in 1.12.1.
- cve_high_underscore crx underscore@1.8.3 has CVE-2026-27601 (high, DoS via unlimited recursion); fixed in 1.13.8.
- cve_moderate_jquery crx jquery@3.4.1 has CVE-2020-11022 and CVE-2020-11023 (moderate XSS); fixed in 3.5.0.
- no_csp manifest content_security_policy is null; no CSP guard while bundling DOM-manipulation libs with active XSS CVEs.
- uninstall_url_hijack crx chrome.runtime.setUninstallURL() set to third-party target on uninstall.
- privacy_policy_unscoped store Policy fetched but scope_extension=false; admits data_collection=true and third_party_sharing=true — v3.5(D) applies.
- broad_host_cookies_webrequest manifest cookies + webRequest + http://*/* + https://*/* = full cross-site traffic and cookie interception.
- function_constructor crx new Function() found in all 3 JS bundles (content, background, popup); dynamic code construction risk.
CVE Exposures (4)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2020-11022 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2020-11023 | jquery@3.4.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- cookies high Can read/write all cookies across all sites via broad host_permissions — affiliate tracking risk.
- storage low Local extension storage only; low standalone risk.
- tabs medium Can read tab URLs and titles; combined with broad host access raises surveillance risk.
- webRequest high Intercepts all HTTP/S requests across all sites; high capability for traffic inspection.
- http://*/* high Broad host permission covering all HTTP sites; enables content script injection everywhere.
- https://*/* high Broad host permission covering all HTTPS sites; enables content script injection everywhere.
Pillar Scores
Permissions7.50
Reputation2.00
Network4.50
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure9.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 09:53
Listing SHA
b3ca694d78d6…
Force block
— not fired
Score recovered
no
Elapsed
—