TextCortex: AI Knowledge Base for Enterprises
hahkojdegblcccihngmgndhdfheheofe
Risk Score
5.29
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE in bundled underscore@1.8.3 (CVE-2021-23358 Arbitrary Code Execution); unfixed, no CSP to mitigate.
- Privacy policy fetch failed; cannot verify data handling adequacy for an AI extension with <all_urls> + scripting.
- No CSP on MV3 extension with broad host access, scripting, and known-vulnerable DOM-manipulation library.
- new Function() constructor usage in background.js combined with <all_urls> host permissions elevates code-exec risk.
- Rating of 1.0 and no developer name listed despite 50K installs raises trust and accountability concerns.
Evidence
- critical_cve_bundled_lib crx underscore@1.8.3 carries CVE-2021-23358 (critical ACE); fixed in 1.12.1, unfixed version bundled.
- high_cve_bundled_lib crx underscore@1.8.3 carries CVE-2026-27601 (high DoS); fixed in 1.13.8, unfixed version bundled.
- no_csp crx content_security_policy is null; no CSP mitigates CVE risk and new Function() usage.
- privacy_policy_fetch_failed api Privacy policy URL returned HTTPError; classification all-false; treated as unfetched → score +10.0.
- function_constructor_in_background crx new Function() in background.js with <all_urls> host permissions and no CSP.
- broad_host_plus_scripting manifest <all_urls> host_permissions + scripting permission; AI extension reads/injects into every page.
- low_rating store Rating is 1.0; no developer name in listing despite 50K installs and enterprise positioning.
- external_hosts_6 crx 6 distinct external JS hosts including workers.dev subdomain (pdf-export-with-template.cderinbogaz.workers.dev).
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- storage low Local state persistence; low standalone risk.
- activeTab medium Grants access to current tab on user action; moderate risk.
- clipboardRead medium Can read clipboard contents; sensitive data exposure possible.
- scripting high Allows programmatic script injection into pages; high capability.
- sidePanel low UI surface only; low standalone risk.
- <all_urls> (host_permissions) high Broad host access across all sites; combined with scripting is critical surface.
Pillar Scores
Permissions6.50
Reputation4.50
Network4.50
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality5.00
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:37
Listing SHA
e61cb00f9407…
Force block
— not fired
Score recovered
no
Elapsed
29.9s