15–25 min Updated

Cross-Site Script Inclusion

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

If you are putting sensitive data in your JavaScript files, an attacker is probably stealing it.

Prevalence
Occasional
Exploitability
Easy
Impact
Harmful

What is cross-site script inclusion (XSSI)?

Cross-site script inclusion (XSSI) is a cross-origin data theft attack in which a malicious website loads a JavaScript file from your domain using a script tag. Browsers do not apply the same-origin policy to script imports, so if the file contains sensitive data about a logged-in user, the attacker's page can read and steal it.

What you'll learn

  • Why script imports are not covered by the same-origin policy
  • How a malicious page reads sensitive data from your JavaScript files
  • How to load user state from a JSON URL instead
  • Cross-Site Script Inclusion lab

    Script files aren't covered by the same-origin policy, so any site can import yours. See what that means for a single-page app that writes each user's API key into its JavaScript: a malicious page imports the file and reads the key.

  • How to prevent Cross-Site Script Inclusion

    The prevention guide covers two approaches:

    • Don't Interpolate Sensitive Data in JavaScript Files
    • Load Page State from a JSON URL
  • Cross-Site Script Inclusion quiz

    Two questions. Passing marks the lesson complete.

Sources

  • Cross-Origin Resource Sharing

    Overly permissive CORS policies can allow malicious websites to access your APIs and steal user data.

  • Cross-Site Request Forgery

    If an attacker can forge HTTP requests to your site, they may be able to trick your users into triggering unintended actions.

  • Cross-Site Scripting

    If your site allows users to add content, you need to be sure that attackers cannot inject malicious JavaScript.

  • Information Leakage

    Revealing system information helps an attacker learn about your tech stack.