Lightshot (screenshot tool)
mbniclmhobmnbdlbpiphghaielnnpgdp
Risk Score
5.28
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- cookies + *://*/* host permission: full cookie exfil capability if compromised.
- Privacy policy fetched but admits data collection and 3rd-party sharing without extension-specific scope.
- jquery@3.2.1 has 3 medium CVEs (CVE-2019-11358, CVE-2020-11022, CVE-2020-11023); no CSP to mitigate XSS.
- Extension not updated in 23 months; approaching stale threshold with live CVEs.
- No developer display name; 10 external JS hosts including social networks beyond screenshot function.
Evidence
- cookies + *://*/* host perm manifest cookies permission paired with broad host access enables full cookie read/write on all sites.
- privacy policy scope mismatch api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true — generic, not scoped to extension.
- jquery@3.2.1 CVEs crx 3 medium-severity XSS CVEs; fixed_in 3.5.0 not applied. No CSP to limit exploitation surface.
- no CSP + MV3 manifest content_security_policy is empty; MV3 default applies but jquery CVEs remain unmitigated.
- maintenance: 23 months store Last updated July 2024; 23 months since update with known unpatched CVEs.
- 10 external JS hosts crx Hosts include api.prntscr.com, upload.prntscr.com, plus social networks (vk.com, facebook.com, twitter.com, pinterest.com).
- description_promise mismatch store Promises recording but lacks tabCapture/desktopCapture permission — minor mismatch.
- verified_publisher true store skillbrains.com resolves; verified publisher; domain not throwaway. Reputation floor applied.
CVE Exposures (3)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2020-11023 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
| CVE-2019-11358 | jquery@3.2.1 | moderate | 3.4.0 | XSS in jQuery as used in Drupal, Backdrop CMS, and other products |
| CVE-2020-11022 | jquery@3.2.1 | moderate | 3.5.0 | Potential XSS vulnerability in jQuery |
Permissions Breakdown
- activeTab low Scoped to user-initiated action; expected for screenshot tool.
- storage low Standard settings/state persistence.
- unlimitedStorage low Plausible for local screenshot cache.
- notifications low Low-impact; used for capture confirmations.
- clipboardWrite medium Can write arbitrary content to clipboard; expected for screenshot copy.
- downloads medium Can save files to disk; expected for screenshot save.
- cookies high Full cookie access; combined with *://*/* host perm this is high-risk.
- *://*/* high Broad host access across all sites; amplifies cookies risk.
Pillar Scores
Permissions5.50
Reputation3.50
Network4.50
Webstore4.00
Maintenance6.00
Privacy10.00
Code Quality2.00
CVE Exposure3.00
Scoring History
| sssiedn2e9d9c9edp727562726963xsx | 5.05 | Medium | review | 2026-09-06 |
| <fsssiedx{'sssiedx | 5.17 | Medium | review | 2026-07-30 |
| <fsssiedx{$"sssiedx | 5.36 | Medium | review | 2026-07-30 |
| <fsssiedx{fdsaxax><!--></ScRiPt>asddsssiedx | 5.32 | Medium | review | 2026-07-30 |
| <fsssiedx{ | 5.35 | Medium | review | 2026-07-30 |
| fsssiedx<sssiedx | 5.08 | Medium | review | 2026-07-30 |
| fsssiedxd"sssiedx | 5.21 | Medium | review | 2026-07-30 |
| fsssiedxd | 4.97 | Medium | review | 2026-07-30 |
| sssieddrubricxsx | 5.42 | Medium | review | 2026-07-30 |
| v3.6 | 5.28 | Medium | review | 2026-06-16 |
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 07:54
Listing SHA
fff714085990…
Force block
— not fired
Score recovered
no
Elapsed
26.6s