Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Markdown Preview Plus

febilkbfcbhebfnokafefeacimjdckgl
Risk Score
5.55
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category DeveloperTools
Installs 90,000
Rating 4.1
Last updated 2026-06-08
Manifest version MV3
CSP present ❌ no
Developer volcas@gmail.com
Verified publisher ✅ yes
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 in bundled underscore@1.8.3 enables arbitrary code execution; unfixed.
  • Privacy policy is Google's generic account policy — does not scope to this extension (D rule: +10.0).
  • new Function() constructor in underscore-min.js combined with no CSP elevates code-execution risk.
  • DOM-XSS sinks (innerHTML) in diagramflowseq.js and jquery.js with no CSP to mitigate.
  • Free-webmail developer (volcas@gmail.com), no dev name, no business domain — unverifiable identity.

Evidence

  • critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE); fixed in 1.12.1. Still bundled at vulnerable version.
  • high_cve_underscore crx underscore@1.8.3 also has CVE-2026-27601 (high, DoS via recursion); fixed in 1.13.8.
  • generic_privacy_policy store Privacy policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → D rule +10.
  • no_csp manifest content_security_policy is null (MV3 strict default applies, but no explicit CSP amplifies CVE+code risk).
  • function_constructor_in_vuln_lib crx new Function() in underscore-min.js (vulnerable version) combined with no CSP raises ACE exploitability.
  • free_webmail_no_devname store Developer email volcas@gmail.com; no developer_name set; floor reputation at 7.5 minus verified discount.
  • verified_publisher store verified_publisher=true; but 0c cap applies due to no dev domain info (developer_domain_info=null).
  • content_scripts_broad manifest Content scripts match *://*/*.*MD* and variants — runs on all HTTP origins serving markdown-like paths.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • storage low Stores user preferences locally; low exfil risk.
  • clipboardWrite medium Can write to clipboard; limited but noteworthy for markdown copy feature.
  • file:///* medium Host permission for local files; required for markdown file preview on disk.
  • content_scripts *://*/*.*MD* medium Content script on broad URL patterns matching markdown file extensions across all HTTP origins.

Pillar Scores

Permissions2.00
Reputation7.00
Network2.00
Webstore1.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:33
Listing SHA 9066c1d802d1…
Force block — not fired
Score recovered no
Elapsed 31.1s