Office Editing for Docs, Sheets & Slides
gbkeegbaiigmenfmjfclcdgdpimamgkj
Risk Score
5.57
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical & high CVEs in bundled lodash@4.5.1 and underscore@1.8.3 (prototype pollution, code injection, arbitrary execution) — all well below fixed versions.
- eval() on variables in mainQOWT.js and require.js enables arbitrary code execution if input is attacker-controlled.
- Privacy policy is Google's generic policy (scope_extension=false, data_collection=true, third_party_sharing=true) — not scoped to this extension.
- cookies permission scoped to *.google.com combined with identity.email exposes Google session context.
- CSP script-src allows localhost ports (4040, 9876, 8712) — likely dev leftovers, potential injection vector on developer machines.
Evidence
- critical_cve_lodash crx lodash@4.5.1 has CVE-2019-10744 (critical prototype pollution); fixed in 4.17.12. Current version far below fix.
- critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical arbitrary code execution); fixed in 1.12.1.
- eval_user_input_mainQOWT crx eval(b) in mainQOWT.js loadModuleFromSource_ — direct eval of variable, code quality HIGH risk.
- generic_privacy_policy store policies.google.com/privacy not scoped to extension; admits data collection and third-party sharing (v3.5 D rule → +10).
- csp_localhost_ports manifest script-src and connect-src include localhost:4040/9876/8712 — dev endpoints left in production CSP.
- featured_by_google store Extension is featured by Google; developer email @google.com domain resolves — reputation partially mitigated.
- no_developer_name store developer_name is empty string; no 'Offered by' display name on listing.
- maintenance_3_6mo store Last updated January 29 2026; months_since_update=7 → maintenance pillar +3.5.
CVE Exposures (11)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2020-28500 | lodash@4.5.1 | moderate | 4.17.21 | Regular Expression Denial of Service (ReDoS) in lodash |
| CVE-2021-23337 | lodash@4.5.1 | high | 4.17.21 | Command Injection in lodash |
| CVE-2026-4800 | lodash@4.5.1 | high | 4.17.21 | Command Injection in lodash |
| CVE-2018-16487 | lodash@4.5.1 | high | 4.17.11 | Prototype Pollution in lodash |
| CVE-2025-13465 | lodash@4.5.1 | moderate | 4.18.0 | lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and |
| CVE-2026-2950 | lodash@4.5.1 | moderate | 4.18.0 | lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and |
| CVE-2018-3721 | lodash@4.5.1 | moderate | 4.17.5 | Prototype Pollution in lodash |
| CVE-2019-10744 | lodash@4.5.1 | critical | 4.17.12 | Prototype Pollution in lodash |
| CVE-2020-8203 | lodash@4.5.1 | high | 4.17.19 | Prototype Pollution in lodash |
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- clipboardRead medium Can read clipboard contents silently.
- clipboardWrite medium Can write to clipboard.
- cookies high Access to cookies across google.com host scope.
- downloads medium Can trigger file downloads.
- fileSystem medium Access to local filesystem; required for Office file editing.
- fileSystem.write medium Write access to local filesystem.
- identity low OAuth token access.
- identity.email medium Exposes user email via OAuth.
- metricsPrivate low Internal Chrome metrics API; restricted to Chromium extensions.
- storage low Standard extension storage.
- unlimitedStorage low No storage quota; low risk alone.
Pillar Scores
Permissions4.50
Reputation3.00
Network2.50
Webstore1.00
Maintenance3.50
Privacy10.00
Code Quality7.50
CVE Exposure9.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-03 07:25
Listing SHA
c87941dc5da4…
Force block
— not fired
Score recovered
no
Elapsed
—