Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

GetEmail.io gets the email of anyone on Earth

hbnjdgffjfjbkdoghlpkedjfoddlgbge
Risk Score
3.77
Risk Level: Low
Recommendation: 🚫 BLOCK
Category Productivity
Installs 90,000
Rating 4.6
Last updated 2026-06-08
Manifest version MV3
CSP present ❌ no
Developer nicolas.bahout@captainleads.com
Verified publisher ❌ no
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • 18 CVEs in bundled lodash@4.8.2, underscore@1.8.3, jquery@2.1.1/3.4.1 including critical prototype pollution and arbitrary code execution — no CSP amplifies XSS risk.
  • Privacy policy URL returns HTTP error (unfetchable) — treated as no policy; extension handles email/PII data with no verifiable disclosure.
  • Install URL hijack redirects to a LinkedIn profile on install — onInstalled opens 3rd-party URL.
  • No developer name listed; no verified publisher badge despite 90k installs and LinkedIn/email-harvest capability.
  • 4 countries of JS host geo-diversity (CA, IE, IN, US) plus 12 external hosts including S3 and clearbit with no CSP restricting outbound connections.

Evidence

  • cve_critical_lodash crx lodash@4.8.2 bundles CVE-2019-10744 (critical prototype pollution) and CVE-2021-23337 (high command injection); fixed_in 4.17.21 not met.
  • cve_critical_underscore crx underscore@1.8.3 bundles CVE-2021-23358 (critical arbitrary code execution); fixed_in 1.12.1 not met.
  • no_csp_with_vuln_libs manifest content_security_policy is null; MV3 with no explicit CSP and multiple DOM-manipulation libs with XSS CVEs.
  • privacy_policy_unfetchable api privacy_policy_classification.fetched=false (HTTPError); policy cannot be evaluated — scored as no policy for email-harvesting tool.
  • install_url_hijack crx install_url_hijack=true; onInstalled opens https://www.linkedin.com/in/mdell/ — 3rd-party URL redirect on install.
  • no_developer_name store developer_name is empty string; no 'Offered by' identity; not a verified publisher despite 90k installs.
  • innerHTML_dom_xss_sink crx dom_sink_innerhtml_userctrl in TabsView.js with no CSP and multiple jquery/lodash XSS CVEs — elevated DOM-XSS risk.
  • geo_diversity_4_countries crx JS hosts span CA, IE, IN, US (4 countries); 12 external hosts including S3, clearbit, multiple getemail.io subdomains.

CVE Exposures (18)

CVELibrarySeverity Fixed inSummary
CVE-2020-28500 lodash@4.8.2 moderate 4.17.21 Regular Expression Denial of Service (ReDoS) in lodash
CVE-2021-23337 lodash@4.8.2 high 4.17.21 Command Injection in lodash
CVE-2018-16487 lodash@4.8.2 high 4.17.11 Prototype Pollution in lodash
CVE-2026-2950 lodash@4.8.2 moderate 4.18.0 lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and
CVE-2018-3721 lodash@4.8.2 moderate 4.17.5 Prototype Pollution in lodash
CVE-2019-10744 lodash@4.8.2 critical 4.17.12 Prototype Pollution in lodash
CVE-2020-8203 lodash@4.8.2 high 4.17.19 Prototype Pollution in lodash
CVE-2026-4800 lodash@4.8.2 high 4.18.0 lodash vulnerable to Code Injection via `_.template` imports key names
CVE-2019-1010266 lodash@4.8.2 moderate 4.17.11 Regular Expression Denial of Service (ReDoS) in lodash
CVE-2025-13465 lodash@4.8.2 moderate 4.17.23 Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS
CVE-2020-11022 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.4.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2019-11358 jquery@2.1.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@2.1.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@2.1.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2015-9251 jquery@2.1.1 moderate 1.12.2 Cross-Site Scripting (XSS) in jquery

Permissions Breakdown

  • storage low Stores extension data locally; low risk on its own.
  • activeTab low Access to current tab only on user action; scoped and transient.
  • host: https://www.linkedin.com/* medium Content script on LinkedIn; can read/modify LinkedIn page data.
  • host: https://*.getemail.io/* medium Broad access to all getemail.io subdomains for API calls.

Pillar Scores

Permissions1.30
Reputation6.50
Network3.00
Webstore4.50
Maintenance0.00
Privacy10.00
Code Quality2.00
CVE Exposure10.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 07:38
Listing SHA 03440a9eb2d5…
Force block — not fired
Score recovered no
Elapsed 56.7s