Stored XSS vulnerability in Reality.eth dApp via governance proposal allows attackers to hijack localStorage RPC URLs and force malicious module execution for curators and arbitrators.
Security & Exploits ·
A stored cross-site scripting vulnerability in Reality.eth, an on-chain fact-checking oracle system, allows attackers to inject malicious code through governance proposal text. The flaw operates by poisoning browser localStorage with attacker-controlled RPC URLs and intercepting Ethereum requests, enabling forced manipulation of answers submitted by curators, arbitrators, and keepers responding to live questions on the platform.
The attack vector exploits a gap in sanitization logic: while Reality.eth's DOMPurify filters markdown content, it processes the title_html field without sanitization and renders it directly via jQuery into the DOM. An attacker submitted a proposal via the permissionless addProposal() function on an abandoned Zodiac Reality Module deployed by Potion DAO, embedding an image tag with JavaScript payload obfuscated via base64 encoding. Since the module queries Reality.eth's shared oracle, the malicious proposal lands in the global question index, triggering execution for any user whose feed displays the entry.
The vulnerability affects any user interacting with Reality.eth while the poisoned proposal remains accessible. It is unclear whether the flaw has been patched, how many users were exposed, or whether additional similar injection points exist in the codebase. The platform's documentation does not currently address this class of vulnerability or recommend defensive practices for users.