Fix escapeString to properly escape HTML-unsafe characters - #1231
Fix escapeString to properly escape HTML-unsafe characters#1231pavankumar-vh wants to merge 1 commit into
Conversation
The escapeString function used JSON.stringify to escape a string, which handles quotes and backslashes but doesn't escape characters that are unsafe in HTML contexts: <, >, &, and '. This is a security concern if the escaped string is used in HTML or XML contexts, as it could allow XSS attacks or HTML injection. Added explicit escaping for these characters to prevent potential security issues.
|
Thanks for looking into A few concrete asks before this is portable:
Right direction, but too speculative to port as-is without knowing the blast radius. |
Overview
Fix a potential XSS vulnerability in the
escapeStringfunction incommon/src/util/string.ts.Bug Description
The
escapeStringfunction usedJSON.stringifyto escape a string, which handles quotes and backslashes but doesn't escape characters that are unsafe in HTML contexts:<,>,&, and'.This is a security concern if the escaped string is used in HTML or XML contexts, as it could allow XSS attacks or HTML injection.
Fix
Added explicit escaping for these characters to prevent potential security issues:
<→\\u003c>→\\u003e&→\\u0026'→\\u0027Testing
No existing tests for this function, but the fix prevents potential XSS vulnerabilities.
Files Changed
common/src/util/string.ts- Added HTML-unsafe character escapingScope
This change only touches
common/which is an approved contribution area per the Contributing Guide.