Skip to content

Fix escapeString to properly escape HTML-unsafe characters - #1231

Open
pavankumar-vh wants to merge 1 commit into
CodebuffAI:mainfrom
pavankumar-vh:fix/escape-string-angular-brackets
Open

Fix escapeString to properly escape HTML-unsafe characters#1231
pavankumar-vh wants to merge 1 commit into
CodebuffAI:mainfrom
pavankumar-vh:fix/escape-string-angular-brackets

Conversation

@pavankumar-vh

Copy link
Copy Markdown

Overview

Fix a potential XSS vulnerability in the escapeString function in common/src/util/string.ts.

Bug Description

The escapeString function used JSON.stringify to escape a string, which handles quotes and backslashes but doesn't escape characters that are unsafe in HTML contexts: <, >, &, and '.

This is a security concern if the escaped string is used in HTML or XML contexts, as it could allow XSS attacks or HTML injection.

Fix

Added explicit escaping for these characters to prevent potential security issues:

  • <\\u003c
  • >\\u003e
  • &\\u0026
  • '\\u0027

Testing

No existing tests for this function, but the fix prevents potential XSS vulnerabilities.

Files Changed

  • common/src/util/string.ts - Added HTML-unsafe character escaping

Scope

This change only touches common/ which is an approved contribution area per the Contributing Guide.

The escapeString function used JSON.stringify to escape a string, which handles
quotes and backslashes but doesn't escape characters that are unsafe in HTML
contexts: <, >, &, and '.

This is a security concern if the escaped string is used in HTML or XML contexts,
as it could allow XSS attacks or HTML injection.

Added explicit escaping for these characters to prevent potential security issues.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant