Topease - AI Assistant for Foreign Trade Client Development
injehaoimkkdminimmmcmbfhcmppjpdf
Risk Score
6.64
Risk Level:
High
Recommendation:
🚫 BLOCK
Top Risks
- Critical CVE in bundled underscore@1.8.3 (Arbitrary Code Execution) with no CSP and DOM-XSS sink present — high exploitability.
- Three medium jQuery CVEs (XSS) in bundled jquery@1.9.1; extension runs on <all_urls> amplifying blast radius.
- Privacy policy is Google's own policy (not scoped to this extension) and admits data collection + 3rd-party sharing — score +10.
- Free-webmail developer (gmail) with no verified publisher badge; developer domain unresolvable — low accountability.
- scripting + <all_urls> + content_scripts on <all_urls> gives full arbitrary JS injection across every visited site.
Evidence
- critical_cve_underscore crx underscore@1.8.3 has CVE-2021-23358 (critical: Arbitrary Code Execution); fixed in 1.12.1.
- high_cve_underscore crx underscore@1.8.3 has CVE-2026-27601 (high: DoS via recursion); fixed in 1.13.8.
- medium_cves_jquery crx jquery@1.9.1 has 3 medium CVEs (CVE-2015-9251, CVE-2019-11358, CVE-2020-11023); fixed in 3.5.0.
- dom_xss_sink_no_csp crx innerHTML from variable in libs/popup.js; no CSP present — DOM-XSS sink unmitigated, scores +2.0 elevated.
- generic_google_privacy_policy store Privacy URL is Google account policy: scope_extension=false, data_collection=true, third_party_sharing=true → +10.
- broad_host_scripting manifest scripting + <all_urls> host_permissions + content_scripts on <all_urls> — full page JS injection on every site.
- free_webmail_dev_no_verified store Developer email shuxinhao2000@gmail.com; no verified publisher badge; developer_domain_info null.
- ai_extension_page_content store AI assistant extension with <all_urls>; processes page content with no scoped privacy disclosure.
CVE Exposures (5)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2019-11358 | jquery@1.9.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11023 | jquery@1.9.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2015-9251 | jquery@1.9.1 | moderate | 1.12.2 | Cross-Site Scripting (XSS) in jquery |
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- scripting high Can inject arbitrary JS into any page; paired with <all_urls> this is maximum code-execution reach.
- tabs medium Access to URL, title, and navigation of all open tabs.
- storage low Persistent local storage; low risk in isolation.
- <all_urls> (host_permissions) high Broad host access amplifies scripting and content_scripts to every site the user visits.
Pillar Scores
Permissions6.50
Reputation6.50
Network5.50
Webstore3.50
Maintenance0.00
Privacy10.00
Code Quality4.00
CVE Exposure8.25
Bookkeeping
Rubric v3.6
Scored at 2026-08-27 16:07
Listing SHA
959379585d41…
Force block
— not fired
Score recovered
no
Elapsed
—