Markdown Preview Plus
febilkbfcbhebfnokafefeacimjdckgl
Risk Score
5.55
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE-2021-23358 in bundled underscore@1.8.3 enables arbitrary code execution; unfixed.
- Privacy policy is Google's generic account policy — does not scope to this extension (D rule: +10.0).
- new Function() constructor in underscore-min.js combined with no CSP elevates code-execution risk.
- DOM-XSS sinks (innerHTML) in diagramflowseq.js and jquery.js with no CSP to mitigate.
- Free-webmail developer (volcas@gmail.com), no dev name, no business domain — unverifiable identity.
Evidence
- critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE); fixed in 1.12.1. Still bundled at vulnerable version.
- high_cve_underscore crx underscore@1.8.3 also has CVE-2026-27601 (high, DoS via recursion); fixed in 1.13.8.
- generic_privacy_policy store Privacy policy URL is Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true → D rule +10.
- no_csp manifest content_security_policy is null (MV3 strict default applies, but no explicit CSP amplifies CVE+code risk).
- function_constructor_in_vuln_lib crx new Function() in underscore-min.js (vulnerable version) combined with no CSP raises ACE exploitability.
- free_webmail_no_devname store Developer email volcas@gmail.com; no developer_name set; floor reputation at 7.5 minus verified discount.
- verified_publisher store verified_publisher=true; but 0c cap applies due to no dev domain info (developer_domain_info=null).
- content_scripts_broad manifest Content scripts match *://*/*.*MD* and variants — runs on all HTTP origins serving markdown-like paths.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- storage low Stores user preferences locally; low exfil risk.
- clipboardWrite medium Can write to clipboard; limited but noteworthy for markdown copy feature.
- file:///* medium Host permission for local files; required for markdown file preview on disk.
- content_scripts *://*/*.*MD* medium Content script on broad URL patterns matching markdown file extensions across all HTTP origins.
Pillar Scores
Permissions2.00
Reputation7.00
Network2.00
Webstore1.50
Maintenance0.00
Privacy10.00
Code Quality5.50
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:33
Listing SHA
9066c1d802d1…
Force block
— not fired
Score recovered
no
Elapsed
31.1s