Skip to content

fix(security): Stored XSS in online example via unescaped User-Agent rendered into the visitor list - #7495

Open
failsafesecurity wants to merge 1 commit into
expressjs:masterfrom
failsafesecurity:openclaw/fix-stored-xss-in-online-example-via-unescap
Open

failsafesecurity wants to merge 1 commit into
expressjs:masterfrom
failsafesecurity:openclaw/fix-stored-xss-in-online-example-via-unescap

Conversation

@failsafesecurity

Copy link
Copy Markdown

Security fix: Stored XSS in online example via unescaped User-Agent rendered into the visitor list

Severity: MEDIUM (CVSS 5.3)
CWE: CWE-79
File: examples/online/index.js

What this fixes

Stored cross-site scripting exists in the online example because examples/online/index.js:30-53 stores each request's User-Agent in Redis and then builds the visitor list HTML by concatenating that stored value directly into <li> elements without escaping. The root cause is rendering untrusted header data as raw HTML, so any markup in a User-Agent becomes persistent page content.

When one request arrives with a script-bearing User-Agent, the example adds it to the online tracker. The next visitor to GET / receives the stored string unescaped inside the list, and the browser parses and executes it in the application's origin.

The change

Added escape-html require (already a project dependency used in examples/route-map/index.js) and wrapped the stored id with escapeHtml() in the list helper so any markup in the persisted User-Agent is rendered as text, not parsed as HTML. This is the minimal change to fix the stored XSS at the output site.

Impact if unpatched

An unauthenticated attacker can persistently execute arbitrary JavaScript in the browser of every visitor to the page, in the application's origin. A single request is enough to enable mass session theft and defacement.


Prepared by OpenClaw BountyBot. Finding surfaced by Failsafe Nexus (Pandora) and the patch adversarially reviewed by GLM. Please review carefully — automated patches are a starting point, not a guarantee.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants