MyBib: Free Citation Generator
phidhnmbkbkbkbknhldmpmnacgicphkf
Risk Score
4.46
Risk Level:
Medium
Recommendation:
🟡 MEDIUM RISK — review
Top Risks
- Critical CVE-2021-23358 in bundled underscore@1.8.3 (Arbitrary Code Execution); fix available at 1.12.1.
- High CVE-2026-27601 in underscore@1.8.3 (DoS via unlimited recursion); fix at 1.13.8.
- Privacy policy fetched but scope_extension=false with data_collection+third_party_sharing=true — policy admits broad data sharing without scoping to this extension.
- scripting + *://*/* grants ability to read and modify content on every website the user visits.
- No CSP declared (MV3 default applies) combined with new Function() constructor in service_worker.js.
Evidence
- critical_cve_bundled_lib crx underscore@1.8.3 has CVE-2021-23358 (critical, Arbitrary Code Execution); fixed in 1.12.1.
- high_cve_bundled_lib crx underscore@1.8.3 has CVE-2026-27601 (high, DoS); fixed in 1.13.8.
- privacy_policy_unscoped_with_sharing api Policy fetched; scope_extension=false, data_collection=true, third_party_sharing=true → +10.0 privacy per v3.5 rule D.
- broad_host_access_with_scripting manifest host_permissions *://*/* + scripting permission allows JS injection on all sites.
- function_constructor_in_service_worker crx new Function() constructor detected in service_worker.js; potential code execution path.
- verified_publisher_featured store Verified publisher + Google Featured badge; reputation discounts applied (capped per 0c: cve_findings non-empty).
- no_csp_declared manifest content_security_policy is null; MV3 default applied, but no explicit CSP hardening.
- high_install_count store 1,000,000 installs; broad blast radius if extension were compromised.
CVE Exposures (2)
| CVE | Library | Severity | Fixed in | Summary |
|---|---|---|---|---|
| CVE-2021-23358 | underscore@1.8.3 | critical | 1.12.1 | Arbitrary Code Execution in underscore |
| CVE-2026-27601 | underscore@1.8.3 | high | 1.13.8 | Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS |
Permissions Breakdown
- clipboardWrite medium Can write to clipboard; reasonable for citation copy feature.
- storage low Local data persistence; standard low-risk permission.
- tabs medium Can read tab URLs and metadata across all open tabs.
- scripting high Can inject scripts into any page; paired with *://*/* = full page access.
- alarms low Periodic background tasks; minimal direct risk.
- *://*/* high Broad host access to all URLs; enables scripting injection on every site visited.
Pillar Scores
Permissions5.50
Reputation2.00
Network2.00
Webstore2.50
Maintenance0.00
Privacy10.00
Code Quality4.50
CVE Exposure7.00
Bookkeeping
Rubric v3.6
Scored at 2026-06-16 10:13
Listing SHA
5c7471ed3888…
Force block
— not fired
Score recovered
no
Elapsed
—