Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Office Editing for Docs, Sheets & Slides

gbkeegbaiigmenfmjfclcdgdpimamgkj
Risk Score
5.57
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs
Rating 3.7
Last updated 2026-01-29 (7 months ago)
Manifest version MV3
CSP present ✅ yes
Developer cros-krk-cws@google.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical & high CVEs in bundled lodash@4.5.1 and underscore@1.8.3 (prototype pollution, code injection, arbitrary execution) — all well below fixed versions.
  • eval() on variables in mainQOWT.js and require.js enables arbitrary code execution if input is attacker-controlled.
  • Privacy policy is Google's generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — not scoped to this extension.
  • cookies permission scoped to *.google.com combined with identity.email exposes Google session context.
  • CSP script-src allows localhost ports (4040, 9876, 8712) — likely dev leftovers, potential injection vector on developer machines.

Evidence

  • critical_cve_lodash crx lodash@4.5.1 has CVE-2019-10744 (critical prototype pollution); fixed in 4.17.12. Current version far below fix.
  • critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical arbitrary code execution); fixed in 1.12.1.
  • eval_user_input_mainQOWT crx eval(b) in mainQOWT.js loadModuleFromSource_ — direct eval of variable, code quality HIGH risk.
  • generic_privacy_policy store policies.google.com/privacy not scoped to extension; admits data collection and third-party sharing (v3.5 D rule → +10).
  • csp_localhost_ports manifest script-src and connect-src include localhost:4040/9876/8712 — dev endpoints left in production CSP.
  • featured_by_google store Extension is featured by Google; developer email @google.com domain resolves — reputation partially mitigated.
  • no_developer_name store developer_name is empty string; no 'Offered by' display name on listing.
  • maintenance_3_6mo store Last updated January 29 2026; months_since_update=7 → maintenance pillar +3.5.

CVE Exposures (11)

CVELibrarySeverity Fixed inSummary
CVE-2020-28500 lodash@4.5.1 moderate 4.17.21 Regular Expression Denial of Service (ReDoS) in lodash
CVE-2021-23337 lodash@4.5.1 high 4.17.21 Command Injection in lodash
CVE-2026-4800 lodash@4.5.1 high 4.17.21 Command Injection in lodash
CVE-2018-16487 lodash@4.5.1 high 4.17.11 Prototype Pollution in lodash
CVE-2025-13465 lodash@4.5.1 moderate 4.18.0 lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and
CVE-2026-2950 lodash@4.5.1 moderate 4.18.0 lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and
CVE-2018-3721 lodash@4.5.1 moderate 4.17.5 Prototype Pollution in lodash
CVE-2019-10744 lodash@4.5.1 critical 4.17.12 Prototype Pollution in lodash
CVE-2020-8203 lodash@4.5.1 high 4.17.19 Prototype Pollution in lodash
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • clipboardRead medium Can read clipboard contents silently.
  • clipboardWrite medium Can write to clipboard.
  • cookies high Access to cookies across google.com host scope.
  • downloads medium Can trigger file downloads.
  • fileSystem medium Access to local filesystem; required for Office file editing.
  • fileSystem.write medium Write access to local filesystem.
  • identity low OAuth token access.
  • identity.email medium Exposes user email via OAuth.
  • metricsPrivate low Internal Chrome metrics API; restricted to Chromium extensions.
  • storage low Standard extension storage.
  • unlimitedStorage low No storage quota; low risk alone.

Pillar Scores

Permissions4.50
Reputation3.00
Network2.50
Webstore1.00
Maintenance3.50
Privacy10.00
Code Quality7.50
CVE Exposure9.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-03 07:25
Listing SHA c87941dc5da4…
Force block — not fired
Score recovered no
Elapsed