Repository navigation
fix(security): Stored XSS in online example via unescaped User-Agent rendered into the visitor list - #7495
Open
failsafesecurity wants to merge 1 commit into
Conversation
…rendered into the visitor list
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Security fix: Stored XSS in online example via unescaped User-Agent rendered into the visitor list
Severity: MEDIUM (CVSS 5.3)
CWE: CWE-79
File:
examples/online/index.jsWhat this fixes
Stored cross-site scripting exists in the online example because examples/online/index.js:30-53 stores each request's User-Agent in Redis and then builds the visitor list HTML by concatenating that stored value directly into
<li>elements without escaping. The root cause is rendering untrusted header data as raw HTML, so any markup in a User-Agent becomes persistent page content.When one request arrives with a script-bearing User-Agent, the example adds it to the online tracker. The next visitor to GET / receives the stored string unescaped inside the list, and the browser parses and executes it in the application's origin.
The change
Added
escape-htmlrequire (already a project dependency used in examples/route-map/index.js) and wrapped the storedidwithescapeHtml()in the list helper so any markup in the persisted User-Agent is rendered as text, not parsed as HTML. This is the minimal change to fix the stored XSS at the output site.Impact if unpatched
An unauthenticated attacker can persistently execute arbitrary JavaScript in the browser of every visitor to the page, in the application's origin. A single request is enough to enable mass session theft and defacement.
Prepared by OpenClaw BountyBot. Finding surfaced by Failsafe Nexus (Pandora) and the patch adversarially reviewed by GLM. Please review carefully — automated patches are a starting point, not a guarantee.