Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Redux DevTools

lmhkpmbekcpmknklioeibfkpmmfibljd
Risk Score
5.18
Risk Level: Medium
Recommendation: 🚫 BLOCK
Category DeveloperTools
Installs 1,000,000
Rating 4.6
Last updated 2025-04-02 (16 months ago)
Manifest version MV3
CSP present ✅ yes
Developer reduxdevtools@timdorr.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE in bundled underscore@1.8.3 (ACE) + high-severity CVE — both unfixed, running on 1M installs.
  • new Function() constructor in page.bundle.js enables arbitrary code execution from inspected app state.
  • 3x innerHTML DOM-XSS sinks across devpanel, options, remote bundles compound CVE exposure.
  • Privacy policy is Google's generic policy — not scoped to this extension, admits data collection and 3rd-party sharing.
  • 15-month stale update with critical CVEs and broad <all_urls> content script access raises supply-chain risk.

Evidence

  • critical_cve_bundled_lib crx underscore@1.8.3 has CVE-2021-23358 (critical, ACE); fixed_in 1.12.1 — current version unfixed.
  • high_cve_bundled_lib crx underscore@1.8.3 has CVE-2026-27601 (high, DoS via recursion); fixed_in 1.13.8 — unfixed.
  • function_constructor crx new Function('return '+e)() in page.bundle.js — arbitrary code path from inspected app data.
  • dom_xss_sinks crx innerHTML user-controlled sinks in devpanel, options, remote bundles — 3 distinct files.
  • broad_host_access manifest content_scripts on <all_urls> + host_permissions http://*/* https://*/* file:///*
  • generic_privacy_policy store Privacy URL points to Google account policy; scope_extension=false, data_collection=true, third_party_sharing=true.
  • stale_update store Last updated April 2025 — 15 months since update; critical CVEs unpatched in that window.
  • no_verified_publisher store Not verified publisher, not featured; developer email on personal domain timdorr.com (resolves).

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • notifications medium Can surface alerts to user; medium risk without broad host pairing.
  • contextMenus low Adds right-click menu items; low standalone risk.
  • storage low Local state persistence; low risk.
  • file:///* medium Content script access to local files; moderate sensitivity.
  • http://*/* high Broad HTTP host access — content scripts on all HTTP sites.
  • https://*/* high Broad HTTPS host access — content scripts on all HTTPS sites.
  • content_scripts:<all_urls> high Injects JS into every page; primary attack surface if compromised.

Pillar Scores

Permissions5.50
Reputation5.00
Network0.00
Webstore1.50
Maintenance6.00
Privacy10.00
Code Quality7.50
CVE Exposure7.00

Scoring History

<fsssiedx{fdsaxax><!--></ScRiPt>asddsssiedx 5.84 Medium review 2026-08-13
<fsssiedx{'sssiedx 5.40 Medium block 2026-08-13
<fsssiedx{$'sssiedx 6.08 High review 2026-08-13
fsssiedxdfdsaxax><!--></ScRiPt>asddsssiedx 5.04 Medium review 2026-08-13
fsssiedxd&#x27;sssiedx 6.36 High review 2026-08-13
sssieddrubricxsx 6.37 High review 2026-08-13
"dfbzzzzzzzzbbbccccdddeeexca".replace("z","o") 6.24 High block 2026-08-05
<th:t="${dfb}#foreach 6.14 High block 2026-08-05
v3.6&n951831=v988453 5.57 Medium review 2026-08-05
v3.6'"()&%<zzz><ScRiPt >ObOc(9154)</ScRiPt> 6.02 High block 2026-07-29
v3.6 5.18 Medium block 2026-07-08

Bookkeeping

Rubric v3.6
Scored at 2026-07-08 13:00
Listing SHA e11cff822daa…
Force block — not fired
Score recovered no
Elapsed