Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

TextCortex: AI Knowledge Base for Enterprises

hahkojdegblcccihngmgndhdfheheofe
Risk Score
5.29
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category AI
Installs 50,000
Rating 1.0
Last updated 2026-06-09
Manifest version MV3
CSP present ❌ no
Developer dev@textcortex.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358 Arbitrary Code Execution); unfixed, no CSP to mitigate.
  • Privacy policy fetch failed; cannot verify data handling adequacy for an AI extension with <all_urls> + scripting.
  • No CSP on MV3 extension with broad host access, scripting, and known-vulnerable DOM-manipulation library.
  • new Function() constructor usage in background.js combined with <all_urls> host permissions elevates code-exec risk.
  • Rating of 1.0 and no developer name listed despite 50K installs raises trust and accountability concerns.

Evidence

  • critical_cve_bundled_lib crx underscore@1.8.3 carries CVE-2021-23358 (critical ACE); fixed in 1.12.1, unfixed version bundled.
  • high_cve_bundled_lib crx underscore@1.8.3 carries CVE-2026-27601 (high DoS); fixed in 1.13.8, unfixed version bundled.
  • no_csp crx content_security_policy is null; no CSP mitigates CVE risk and new Function() usage.
  • privacy_policy_fetch_failed api Privacy policy URL returned HTTPError; classification all-false; treated as unfetched → score +10.0.
  • function_constructor_in_background crx new Function() in background.js with <all_urls> host permissions and no CSP.
  • broad_host_plus_scripting manifest <all_urls> host_permissions + scripting permission; AI extension reads/injects into every page.
  • low_rating store Rating is 1.0; no developer name in listing despite 50K installs and enterprise positioning.
  • external_hosts_6 crx 6 distinct external JS hosts including workers.dev subdomain (pdf-export-with-template.cderinbogaz.workers.dev).

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • storage low Local state persistence; low standalone risk.
  • activeTab medium Grants access to current tab on user action; moderate risk.
  • clipboardRead medium Can read clipboard contents; sensitive data exposure possible.
  • scripting high Allows programmatic script injection into pages; high capability.
  • sidePanel low UI surface only; low standalone risk.
  • <all_urls> (host_permissions) high Broad host access across all sites; combined with scripting is critical surface.

Pillar Scores

Permissions6.50
Reputation4.50
Network4.50
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:37
Listing SHA e61cb00f9407…
Force block — not fired
Score recovered no
Elapsed 29.9s