Tanks Game
kmiidcaojgeepjlccoalkdimgpfnbagj
Risk Score
4.58
Risk Level:
Medium
Recommendation:
🚫 BLOCK
Top Risks
- Critical CVE-2021-23358 (arbitrary code execution) in bundled underscore@1.8.3 — well below fixed version 1.12.1
- eval_user_input in opus.wasm.js: direct eval() of variable enabling arbitrary code execution
- Privacy policy hosted on cdn.cloudapi.stream is not scoped to this extension and admits third-party sharing
- Uninstall URL hijack flagged; install_url_hijack opens popup/index.html — redirect hooks present
- CSP allows unsafe-eval and unsafe-inline on script-src, undermining XSS protections despite CSP presence
Evidence
- critical_cve_bundled_lib crx underscore@1.8.3 has CVE-2021-23358 (critical, arbitrary code execution); fixed in 1.12.1
- high_cve_bundled_lib crx underscore@1.8.3 has CVE-2026-27601 (high, DoS via recursion); fixed in 1.13.8
- eval_user_input crx Direct eval() of funcstr in popup/scripts/opus.wasm.js — code quality HIGH risk
- dom_sink_innerhtml crx innerHTML from userAgent in supportcheck.js; CSP has unsafe-eval so XSS mitigations weak
- unsafe_csp manifest CSP allows 'unsafe-eval' and 'unsafe-inline' on script-src for both extension_pages and sandbox
- privacy_policy_inadequate store Policy on cdn.cloudapi.stream: scope_extension=false, data_collection=false, third_party_sharing=true
- uninstall_url_hijack crx uninstall_url_hijack=true and install_url_hijack=true flagged in manifest analysis
- free_webmail_dev_no_name store Developer email viktornadiezhdin@gmail.com with no developer_name listed
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Pillar Scores
Permissions0.00
Reputation5.00
Network2.00
Webstore5.00
Maintenance1.50
Privacy9.00
Code Quality6.00
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-08-28 08:26
Listing SHA
af4bc82eb6b4…
Force block
— not fired
Score recovered
no
Elapsed
—