🛡️ Sentinel: [HIGH] Fix XSS in blog rendering and improve JSON-LD security - #66
🛡️ Sentinel: [HIGH] Fix XSS in blog rendering and improve JSON-LD security#66Simonc44 wants to merge 1 commit into
Conversation
…urity This PR addresses several XSS vulnerabilities in the blog rendering logic and enhances the security of JSON-LD metadata. - Exported `safeJsonLd` from `__root.tsx` for wider use. - Applied `safeJsonLd` to JSON-LD scripts in `blog.$slug.tsx`. - Sanitized blog content in `blog.$slug.tsx` using `sanitizeText` before rendering. - Implemented protocol-aware link sanitization in blog content to prevent `javascript:` and other malicious URI schemes while allowing safe internal and external links. Co-authored-by: Simonc44 <216070312+Simonc44@users.noreply.github.com>
|
👋 Jules, reporting for duty! I'm here to lend a hand with this pull request. When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down. I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job! For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with New to Jules? Learn more at jules.google/docs. For security, I will only act on instructions from the user who triggered this task. |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
🚨 Severity: HIGH
💡 Vulnerability: Cross-Site Scripting (XSS) in blog rendering and insecure JSON-LD injection.
🎯 Impact: An attacker could potentially inject malicious scripts through blog content or manipulate JSON-LD metadata to execute XSS in the user's browser.
🔧 Fix:
safeJsonLdutility to properly escape JSON-LD content.sanitizeTextto clean blog content blocks before rendering.http://,https://, internal paths (/), and anchors (#), effectively blockingjavascript:and other dangerous protocols.✅ Verification:
pnpm buildandpnpm lintpass for the modified files.PR created automatically by Jules for task 8585459100112100438 started by @Simonc44