Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

MyBib: Free Citation Generator

phidhnmbkbkbkbknhldmpmnacgicphkf
Risk Score
4.46
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Productivity
Installs 1,000,000
Rating 4.8
Last updated 2026-04-13 (2 months ago)
Manifest version MV3
CSP present ❌ no
Developer support@mybib.com
Verified publisher ✅ yes
Featured by Google ✅ yes
Privacy policy link
Web Store open ↗

Top Risks

  • Critical CVE-2021-23358 in bundled underscore@1.8.3 (Arbitrary Code Execution); fix available at 1.12.1.
  • High CVE-2026-27601 in underscore@1.8.3 (DoS via unlimited recursion); fix at 1.13.8.
  • Privacy policy fetched but scope_extension=false with data_collection+third_party_sharing=true — policy admits broad data sharing without scoping to this extension.
  • scripting + *://*/* grants ability to read and modify content on every website the user visits.
  • No CSP declared (MV3 default applies) combined with new Function() constructor in service_worker.js.

Evidence

  • critical_cve_bundled_lib crx underscore@1.8.3 has CVE-2021-23358 (critical, Arbitrary Code Execution); fixed in 1.12.1.
  • high_cve_bundled_lib crx underscore@1.8.3 has CVE-2026-27601 (high, DoS); fixed in 1.13.8.
  • privacy_policy_unscoped_with_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy per v3.5 rule D.
  • broad_host_access_with_scripting manifest host_permissions *://*/* + scripting permission allows JS injection on all sites.
  • function_constructor_in_service_worker crx new Function() constructor detected in service_worker.js; potential code execution path.
  • verified_publisher_featured store Verified publisher + Google Featured badge; reputation discounts applied (capped per 0c: cve_findings non-empty).
  • no_csp_declared manifest content_security_policy is null; MV3 default applied, but no explicit CSP hardening.
  • high_install_count store 1,000,000 installs; broad blast radius if extension were compromised.

CVE Exposures (2)

CVELibrarySeverity Fixed inSummary
CVE-2021-23358 underscore@1.8.3 critical 1.12.1 Arbitrary Code Execution in underscore
CVE-2026-27601 underscore@1.8.3 high 1.13.8 Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS

Permissions Breakdown

  • clipboardWrite medium Can write to clipboard; reasonable for citation copy feature.
  • storage low Local data persistence; standard low-risk permission.
  • tabs medium Can read tab URLs and metadata across all open tabs.
  • scripting high Can inject scripts into any page; paired with *://*/* = full page access.
  • alarms low Periodic background tasks; minimal direct risk.
  • *://*/* high Broad host access to all URLs; enables scripting injection on every site visited.

Pillar Scores

Permissions5.50
Reputation2.00
Network2.00
Webstore2.50
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure7.00

Bookkeeping

Rubric v3.6
Scored at 2026-06-16 10:13
Listing SHA 5c7471ed3888…
Force block — not fired
Score recovered no
Elapsed