harden: add output encoding in form-requests.vue - #1925

Open
anupamme wants to merge 1 commit into
ProcessMaker:developfrom
anupamme:fix-repo-screen-builder-xss-event-handler-sanitization
Open

harden: add output encoding in form-requests.vue#1925
anupamme wants to merge 1 commit into
ProcessMaker:developfrom
anupamme:fix-repo-screen-builder-xss-event-handler-sanitization

Conversation

@anupamme

Copy link
Copy Markdown

Summary

Harden input handling in src/components/renderer/form-requests.vue (flagged by multi_agent_ai).

Vulnerability

FieldValue
IDV-001
SeverityHIGH
Scannermulti_agent_ai
RuleV-001
Filesrc/components/renderer/form-requests.vue:22
AssessmentDefensive hardening
CWECWE-79

Description: The components use Vue's v-html directive to render HTML content. While a sanitize() function is called, its implementation is not visible in the provided code. The sanitizeTooltip() function in form-tasks.vue uses regex-based filtering which may be bypassable. Multiple methods construct HTML strings that are rendered via v-html, creating XSS risk if sanitization is insufficient.

Threat Model Context

This is a Node.js library - vulnerabilities affect downstream consumers who use this package.

Changes

  • src/mixins/datatable.js

Behavior Preservation

The change is scoped to 1 file on the vulnerable path; it only tightens handling of untrusted input and leaves valid inputs unaffected.

Security Invariant

Property: User-supplied strings in HTTP responses are HTML-escaped

Regression test
const{ mount }=require('@vue/test-utils');constFormRequests=require('src/components/renderer/form-requests.vue').default;describe("User-supplied strings in HTTP responses are HTML-escaped",()=>{constpayloads=[{input: '<script>alert(1)</script>',description: 'script tag payload'},{input: '<img onerror=alert(1) src=x>',description: 'event handler payload'},{input: '"><svg onload=alert(1)>',description: 'attribute break payload'},{input: 'normal text',description: 'valid input'},{input: '',description: 'empty string boundary'}];test.each(payloads)("sanitizes adversarial input: $description",async({ input })=>{constwrapper=mount(FormRequests,{propsData: {row: {testField: input},header: 'testField'}});// Wait for Vue to renderawaitwrapper.vm.$nextTick();// Get the actual rendered HTMLconstrenderedHtml=wrapper.html();// Check that raw dangerous sequences are not presentexpect(renderedHtml).not.toContain('<script>');expect(renderedHtml).not.toContain('onerror=');expect(renderedHtml).not.toContain('onload=');// Verify the content is properly escaped or sanitized// Either the input should be escaped (contain &lt; etc) or removedif(input.includes('<')){expect(renderedHtml).toMatch(/&lt;|&#x3C;/);}// Verify v-html directive is not rendering raw dangerous HTMLconstspanElement=wrapper.find('span');expect(spanElement.exists()).toBe(true);// Check that inner HTML doesn't contain unescaped dangerous tagsconstinnerHtml=spanElement.element.innerHTML;constdangerousPatterns=[/<script/i,/onerror=/i,/onload=/i];dangerousPatterns.forEach(pattern=>{expect(innerHtml).not.toMatch(pattern);});});});

This test guards against regressions — it's useful independent of the code change above.


This patch removes an exploit primitive — a code pattern that, while not independently exploitable today, could be chained with other weaknesses by automated exploit-development tooling. Proactive removal of such primitives raises the bar against increasingly capable automated attack tools.


Automated security fix by OrbisAI Security

Automated security fix generated by OrbisAI Security
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@anupamme
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

harden: add output encoding in form-requests.vue - #1925

Open
anupamme wants to merge 1 commit into
ProcessMaker:developfrom
anupamme:fix-repo-screen-builder-xss-event-handler-sanitization
Open

harden: add output encoding in form-requests.vue#1925
anupamme wants to merge 1 commit into
ProcessMaker:developfrom
anupamme:fix-repo-screen-builder-xss-event-handler-sanitization

Conversation

@anupamme

Copy link
Copy Markdown

Summary

Harden input handling in src/components/renderer/form-requests.vue (flagged by multi_agent_ai).

Vulnerability

FieldValue
IDV-001
SeverityHIGH
Scannermulti_agent_ai
RuleV-001
Filesrc/components/renderer/form-requests.vue:22
AssessmentDefensive hardening
CWECWE-79

Description: The components use Vue's v-html directive to render HTML content. While a sanitize() function is called, its implementation is not visible in the provided code. The sanitizeTooltip() function in form-tasks.vue uses regex-based filtering which may be bypassable. Multiple methods construct HTML strings that are rendered via v-html, creating XSS risk if sanitization is insufficient.

Threat Model Context

This is a Node.js library - vulnerabilities affect downstream consumers who use this package.

Changes

  • src/mixins/datatable.js

Behavior Preservation

The change is scoped to 1 file on the vulnerable path; it only tightens handling of untrusted input and leaves valid inputs unaffected.

Security Invariant

Property: User-supplied strings in HTTP responses are HTML-escaped

Regression test
const{ mount }=require('@vue/test-utils');constFormRequests=require('src/components/renderer/form-requests.vue').default;describe("User-supplied strings in HTTP responses are HTML-escaped",()=>{constpayloads=[{input: '<script>alert(1)</script>',description: 'script tag payload'},{input: '<img onerror=alert(1) src=x>',description: 'event handler payload'},{input: '"><svg onload=alert(1)>',description: 'attribute break payload'},{input: 'normal text',description: 'valid input'},{input: '',description: 'empty string boundary'}];test.each(payloads)("sanitizes adversarial input: $description",async({ input })=>{constwrapper=mount(FormRequests,{propsData: {row: {testField: input},header: 'testField'}});// Wait for Vue to renderawaitwrapper.vm.$nextTick();// Get the actual rendered HTMLconstrenderedHtml=wrapper.html();// Check that raw dangerous sequences are not presentexpect(renderedHtml).not.toContain('<script>');expect(renderedHtml).not.toContain('onerror=');expect(renderedHtml).not.toContain('onload=');// Verify the content is properly escaped or sanitized// Either the input should be escaped (contain &lt; etc) or removedif(input.includes('<')){expect(renderedHtml).toMatch(/&lt;|&#x3C;/);}// Verify v-html directive is not rendering raw dangerous HTMLconstspanElement=wrapper.find('span');expect(spanElement.exists()).toBe(true);// Check that inner HTML doesn't contain unescaped dangerous tagsconstinnerHtml=spanElement.element.innerHTML;constdangerousPatterns=[/<script/i,/onerror=/i,/onload=/i];dangerousPatterns.forEach(pattern=>{expect(innerHtml).not.toMatch(pattern);});});});

This test guards against regressions — it's useful independent of the code change above.


This patch removes an exploit primitive — a code pattern that, while not independently exploitable today, could be chained with other weaknesses by automated exploit-development tooling. Proactive removal of such primitives raises the bar against increasingly capable automated attack tools.


Automated security fix by OrbisAI Security

Automated security fix generated by OrbisAI Security
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@anupamme
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

harden: add output encoding in form-requests.vue - #1925

Open
anupamme wants to merge 1 commit into
ProcessMaker:developfrom
anupamme:fix-repo-screen-builder-xss-event-handler-sanitization
Open

harden: add output encoding in form-requests.vue#1925
anupamme wants to merge 1 commit into
ProcessMaker:developfrom
anupamme:fix-repo-screen-builder-xss-event-handler-sanitization

Conversation

@anupamme

Copy link
Copy Markdown

Summary

Harden input handling in src/components/renderer/form-requests.vue (flagged by multi_agent_ai).

Vulnerability

FieldValue
IDV-001
SeverityHIGH
Scannermulti_agent_ai
RuleV-001
Filesrc/components/renderer/form-requests.vue:22
AssessmentDefensive hardening
CWECWE-79

Description: The components use Vue's v-html directive to render HTML content. While a sanitize() function is called, its implementation is not visible in the provided code. The sanitizeTooltip() function in form-tasks.vue uses regex-based filtering which may be bypassable. Multiple methods construct HTML strings that are rendered via v-html, creating XSS risk if sanitization is insufficient.

Threat Model Context

This is a Node.js library - vulnerabilities affect downstream consumers who use this package.

Changes

  • src/mixins/datatable.js

Behavior Preservation

The change is scoped to 1 file on the vulnerable path; it only tightens handling of untrusted input and leaves valid inputs unaffected.

Security Invariant

Property: User-supplied strings in HTTP responses are HTML-escaped

Regression test
const{ mount }=require('@vue/test-utils');constFormRequests=require('src/components/renderer/form-requests.vue').default;describe("User-supplied strings in HTTP responses are HTML-escaped",()=>{constpayloads=[{input: '<script>alert(1)</script>',description: 'script tag payload'},{input: '<img onerror=alert(1) src=x>',description: 'event handler payload'},{input: '"><svg onload=alert(1)>',description: 'attribute break payload'},{input: 'normal text',description: 'valid input'},{input: '',description: 'empty string boundary'}];test.each(payloads)("sanitizes adversarial input: $description",async({ input })=>{constwrapper=mount(FormRequests,{propsData: {row: {testField: input},header: 'testField'}});// Wait for Vue to renderawaitwrapper.vm.$nextTick();// Get the actual rendered HTMLconstrenderedHtml=wrapper.html();// Check that raw dangerous sequences are not presentexpect(renderedHtml).not.toContain('<script>');expect(renderedHtml).not.toContain('onerror=');expect(renderedHtml).not.toContain('onload=');// Verify the content is properly escaped or sanitized// Either the input should be escaped (contain &lt; etc) or removedif(input.includes('<')){expect(renderedHtml).toMatch(/&lt;|&#x3C;/);}// Verify v-html directive is not rendering raw dangerous HTMLconstspanElement=wrapper.find('span');expect(spanElement.exists()).toBe(true);// Check that inner HTML doesn't contain unescaped dangerous tagsconstinnerHtml=spanElement.element.innerHTML;constdangerousPatterns=[/<script/i,/onerror=/i,/onload=/i];dangerousPatterns.forEach(pattern=>{expect(innerHtml).not.toMatch(pattern);});});});

This test guards against regressions — it's useful independent of the code change above.


This patch removes an exploit primitive — a code pattern that, while not independently exploitable today, could be chained with other weaknesses by automated exploit-development tooling. Proactive removal of such primitives raises the bar against increasingly capable automated attack tools.


Automated security fix by OrbisAI Security

Automated security fix generated by OrbisAI Security
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@anupamme
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

harden: add output encoding in form-requests.vue - #1925

Open
anupamme wants to merge 1 commit into
ProcessMaker:developfrom
anupamme:fix-repo-screen-builder-xss-event-handler-sanitization
Open

harden: add output encoding in form-requests.vue#1925
anupamme wants to merge 1 commit into
ProcessMaker:developfrom
anupamme:fix-repo-screen-builder-xss-event-handler-sanitization

Conversation

@anupamme

Copy link
Copy Markdown

Summary

Harden input handling in src/components/renderer/form-requests.vue (flagged by multi_agent_ai).

Vulnerability

FieldValue
IDV-001
SeverityHIGH
Scannermulti_agent_ai
RuleV-001
Filesrc/components/renderer/form-requests.vue:22
AssessmentDefensive hardening
CWECWE-79

Description: The components use Vue's v-html directive to render HTML content. While a sanitize() function is called, its implementation is not visible in the provided code. The sanitizeTooltip() function in form-tasks.vue uses regex-based filtering which may be bypassable. Multiple methods construct HTML strings that are rendered via v-html, creating XSS risk if sanitization is insufficient.

Threat Model Context

This is a Node.js library - vulnerabilities affect downstream consumers who use this package.

Changes

  • src/mixins/datatable.js

Behavior Preservation

The change is scoped to 1 file on the vulnerable path; it only tightens handling of untrusted input and leaves valid inputs unaffected.

Security Invariant

Property: User-supplied strings in HTTP responses are HTML-escaped

Regression test
const{ mount }=require('@vue/test-utils');constFormRequests=require('src/components/renderer/form-requests.vue').default;describe("User-supplied strings in HTTP responses are HTML-escaped",()=>{constpayloads=[{input: '<script>alert(1)</script>',description: 'script tag payload'},{input: '<img onerror=alert(1) src=x>',description: 'event handler payload'},{input: '"><svg onload=alert(1)>',description: 'attribute break payload'},{input: 'normal text',description: 'valid input'},{input: '',description: 'empty string boundary'}];test.each(payloads)("sanitizes adversarial input: $description",async({ input })=>{constwrapper=mount(FormRequests,{propsData: {row: {testField: input},header: 'testField'}});// Wait for Vue to renderawaitwrapper.vm.$nextTick();// Get the actual rendered HTMLconstrenderedHtml=wrapper.html();// Check that raw dangerous sequences are not presentexpect(renderedHtml).not.toContain('<script>');expect(renderedHtml).not.toContain('onerror=');expect(renderedHtml).not.toContain('onload=');// Verify the content is properly escaped or sanitized// Either the input should be escaped (contain &lt; etc) or removedif(input.includes('<')){expect(renderedHtml).toMatch(/&lt;|&#x3C;/);}// Verify v-html directive is not rendering raw dangerous HTMLconstspanElement=wrapper.find('span');expect(spanElement.exists()).toBe(true);// Check that inner HTML doesn't contain unescaped dangerous tagsconstinnerHtml=spanElement.element.innerHTML;constdangerousPatterns=[/<script/i,/onerror=/i,/onload=/i];dangerousPatterns.forEach(pattern=>{expect(innerHtml).not.toMatch(pattern);});});});

This test guards against regressions — it's useful independent of the code change above.


This patch removes an exploit primitive — a code pattern that, while not independently exploitable today, could be chained with other weaknesses by automated exploit-development tooling. Proactive removal of such primitives raises the bar against increasingly capable automated attack tools.


Automated security fix by OrbisAI Security

Automated security fix generated by OrbisAI Security
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@anupamme
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

harden: add output encoding in form-requests.vue - #1925

Open
anupamme wants to merge 1 commit into
ProcessMaker:developfrom
anupamme:fix-repo-screen-builder-xss-event-handler-sanitization
Open

harden: add output encoding in form-requests.vue#1925
anupamme wants to merge 1 commit into
ProcessMaker:developfrom
anupamme:fix-repo-screen-builder-xss-event-handler-sanitization

Conversation

@anupamme

Copy link
Copy Markdown

Summary

Harden input handling in src/components/renderer/form-requests.vue (flagged by multi_agent_ai).

Vulnerability

FieldValue
IDV-001
SeverityHIGH
Scannermulti_agent_ai
RuleV-001
Filesrc/components/renderer/form-requests.vue:22
AssessmentDefensive hardening
CWECWE-79

Description: The components use Vue's v-html directive to render HTML content. While a sanitize() function is called, its implementation is not visible in the provided code. The sanitizeTooltip() function in form-tasks.vue uses regex-based filtering which may be bypassable. Multiple methods construct HTML strings that are rendered via v-html, creating XSS risk if sanitization is insufficient.

Threat Model Context

This is a Node.js library - vulnerabilities affect downstream consumers who use this package.

Changes

  • src/mixins/datatable.js

Behavior Preservation

The change is scoped to 1 file on the vulnerable path; it only tightens handling of untrusted input and leaves valid inputs unaffected.

Security Invariant

Property: User-supplied strings in HTTP responses are HTML-escaped

Regression test
const{ mount }=require('@vue/test-utils');constFormRequests=require('src/components/renderer/form-requests.vue').default;describe("User-supplied strings in HTTP responses are HTML-escaped",()=>{constpayloads=[{input: '<script>alert(1)</script>',description: 'script tag payload'},{input: '<img onerror=alert(1) src=x>',description: 'event handler payload'},{input: '"><svg onload=alert(1)>',description: 'attribute break payload'},{input: 'normal text',description: 'valid input'},{input: '',description: 'empty string boundary'}];test.each(payloads)("sanitizes adversarial input: $description",async({ input })=>{constwrapper=mount(FormRequests,{propsData: {row: {testField: input},header: 'testField'}});// Wait for Vue to renderawaitwrapper.vm.$nextTick();// Get the actual rendered HTMLconstrenderedHtml=wrapper.html();// Check that raw dangerous sequences are not presentexpect(renderedHtml).not.toContain('<script>');expect(renderedHtml).not.toContain('onerror=');expect(renderedHtml).not.toContain('onload=');// Verify the content is properly escaped or sanitized// Either the input should be escaped (contain &lt; etc) or removedif(input.includes('<')){expect(renderedHtml).toMatch(/&lt;|&#x3C;/);}// Verify v-html directive is not rendering raw dangerous HTMLconstspanElement=wrapper.find('span');expect(spanElement.exists()).toBe(true);// Check that inner HTML doesn't contain unescaped dangerous tagsconstinnerHtml=spanElement.element.innerHTML;constdangerousPatterns=[/<script/i,/onerror=/i,/onload=/i];dangerousPatterns.forEach(pattern=>{expect(innerHtml).not.toMatch(pattern);});});});

This test guards against regressions — it's useful independent of the code change above.


This patch removes an exploit primitive — a code pattern that, while not independently exploitable today, could be chained with other weaknesses by automated exploit-development tooling. Proactive removal of such primitives raises the bar against increasingly capable automated attack tools.


Automated security fix by OrbisAI Security

Automated security fix generated by OrbisAI Security
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@anupamme
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

harden: add output encoding in form-requests.vue - #1925

Open
anupamme wants to merge 1 commit into
ProcessMaker:developfrom
anupamme:fix-repo-screen-builder-xss-event-handler-sanitization
Open

harden: add output encoding in form-requests.vue#1925
anupamme wants to merge 1 commit into
ProcessMaker:developfrom
anupamme:fix-repo-screen-builder-xss-event-handler-sanitization

Conversation

@anupamme

Copy link
Copy Markdown

Summary

Harden input handling in src/components/renderer/form-requests.vue (flagged by multi_agent_ai).

Vulnerability

FieldValue
IDV-001
SeverityHIGH
Scannermulti_agent_ai
RuleV-001
Filesrc/components/renderer/form-requests.vue:22
AssessmentDefensive hardening
CWECWE-79

Description: The components use Vue's v-html directive to render HTML content. While a sanitize() function is called, its implementation is not visible in the provided code. The sanitizeTooltip() function in form-tasks.vue uses regex-based filtering which may be bypassable. Multiple methods construct HTML strings that are rendered via v-html, creating XSS risk if sanitization is insufficient.

Threat Model Context

This is a Node.js library - vulnerabilities affect downstream consumers who use this package.

Changes

  • src/mixins/datatable.js

Behavior Preservation

The change is scoped to 1 file on the vulnerable path; it only tightens handling of untrusted input and leaves valid inputs unaffected.

Security Invariant

Property: User-supplied strings in HTTP responses are HTML-escaped

Regression test
const{ mount }=require('@vue/test-utils');constFormRequests=require('src/components/renderer/form-requests.vue').default;describe("User-supplied strings in HTTP responses are HTML-escaped",()=>{constpayloads=[{input: '<script>alert(1)</script>',description: 'script tag payload'},{input: '<img onerror=alert(1) src=x>',description: 'event handler payload'},{input: '"><svg onload=alert(1)>',description: 'attribute break payload'},{input: 'normal text',description: 'valid input'},{input: '',description: 'empty string boundary'}];test.each(payloads)("sanitizes adversarial input: $description",async({ input })=>{constwrapper=mount(FormRequests,{propsData: {row: {testField: input},header: 'testField'}});// Wait for Vue to renderawaitwrapper.vm.$nextTick();// Get the actual rendered HTMLconstrenderedHtml=wrapper.html();// Check that raw dangerous sequences are not presentexpect(renderedHtml).not.toContain('<script>');expect(renderedHtml).not.toContain('onerror=');expect(renderedHtml).not.toContain('onload=');// Verify the content is properly escaped or sanitized// Either the input should be escaped (contain &lt; etc) or removedif(input.includes('<')){expect(renderedHtml).toMatch(/&lt;|&#x3C;/);}// Verify v-html directive is not rendering raw dangerous HTMLconstspanElement=wrapper.find('span');expect(spanElement.exists()).toBe(true);// Check that inner HTML doesn't contain unescaped dangerous tagsconstinnerHtml=spanElement.element.innerHTML;constdangerousPatterns=[/<script/i,/onerror=/i,/onload=/i];dangerousPatterns.forEach(pattern=>{expect(innerHtml).not.toMatch(pattern);});});});

This test guards against regressions — it's useful independent of the code change above.


This patch removes an exploit primitive — a code pattern that, while not independently exploitable today, could be chained with other weaknesses by automated exploit-development tooling. Proactive removal of such primitives raises the bar against increasingly capable automated attack tools.


Automated security fix by OrbisAI Security

Automated security fix generated by OrbisAI Security
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@anupamme
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

harden: add output encoding in form-requests.vue - #1925

Open
anupamme wants to merge 1 commit into
ProcessMaker:developfrom
anupamme:fix-repo-screen-builder-xss-event-handler-sanitization
Open

harden: add output encoding in form-requests.vue#1925
anupamme wants to merge 1 commit into
ProcessMaker:developfrom
anupamme:fix-repo-screen-builder-xss-event-handler-sanitization

Conversation

@anupamme

Copy link
Copy Markdown

Summary

Harden input handling in src/components/renderer/form-requests.vue (flagged by multi_agent_ai).

Vulnerability

FieldValue
IDV-001
SeverityHIGH
Scannermulti_agent_ai
RuleV-001
Filesrc/components/renderer/form-requests.vue:22
AssessmentDefensive hardening
CWECWE-79

Description: The components use Vue's v-html directive to render HTML content. While a sanitize() function is called, its implementation is not visible in the provided code. The sanitizeTooltip() function in form-tasks.vue uses regex-based filtering which may be bypassable. Multiple methods construct HTML strings that are rendered via v-html, creating XSS risk if sanitization is insufficient.

Threat Model Context

This is a Node.js library - vulnerabilities affect downstream consumers who use this package.

Changes

  • src/mixins/datatable.js

Behavior Preservation

The change is scoped to 1 file on the vulnerable path; it only tightens handling of untrusted input and leaves valid inputs unaffected.

Security Invariant

Property: User-supplied strings in HTTP responses are HTML-escaped

Regression test
const{ mount }=require('@vue/test-utils');constFormRequests=require('src/components/renderer/form-requests.vue').default;describe("User-supplied strings in HTTP responses are HTML-escaped",()=>{constpayloads=[{input: '<script>alert(1)</script>',description: 'script tag payload'},{input: '<img onerror=alert(1) src=x>',description: 'event handler payload'},{input: '"><svg onload=alert(1)>',description: 'attribute break payload'},{input: 'normal text',description: 'valid input'},{input: '',description: 'empty string boundary'}];test.each(payloads)("sanitizes adversarial input: $description",async({ input })=>{constwrapper=mount(FormRequests,{propsData: {row: {testField: input},header: 'testField'}});// Wait for Vue to renderawaitwrapper.vm.$nextTick();// Get the actual rendered HTMLconstrenderedHtml=wrapper.html();// Check that raw dangerous sequences are not presentexpect(renderedHtml).not.toContain('<script>');expect(renderedHtml).not.toContain('onerror=');expect(renderedHtml).not.toContain('onload=');// Verify the content is properly escaped or sanitized// Either the input should be escaped (contain &lt; etc) or removedif(input.includes('<')){expect(renderedHtml).toMatch(/&lt;|&#x3C;/);}// Verify v-html directive is not rendering raw dangerous HTMLconstspanElement=wrapper.find('span');expect(spanElement.exists()).toBe(true);// Check that inner HTML doesn't contain unescaped dangerous tagsconstinnerHtml=spanElement.element.innerHTML;constdangerousPatterns=[/<script/i,/onerror=/i,/onload=/i];dangerousPatterns.forEach(pattern=>{expect(innerHtml).not.toMatch(pattern);});});});

This test guards against regressions — it's useful independent of the code change above.


This patch removes an exploit primitive — a code pattern that, while not independently exploitable today, could be chained with other weaknesses by automated exploit-development tooling. Proactive removal of such primitives raises the bar against increasingly capable automated attack tools.


Automated security fix by OrbisAI Security

Automated security fix generated by OrbisAI Security
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@anupamme
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

harden: add output encoding in form-requests.vue - #1925

Open
anupamme wants to merge 1 commit into
ProcessMaker:developfrom
anupamme:fix-repo-screen-builder-xss-event-handler-sanitization
Open

harden: add output encoding in form-requests.vue#1925
anupamme wants to merge 1 commit into
ProcessMaker:developfrom
anupamme:fix-repo-screen-builder-xss-event-handler-sanitization

Conversation

@anupamme

Copy link
Copy Markdown

Summary

Harden input handling in src/components/renderer/form-requests.vue (flagged by multi_agent_ai).

Vulnerability

FieldValue
IDV-001
SeverityHIGH
Scannermulti_agent_ai
RuleV-001
Filesrc/components/renderer/form-requests.vue:22
AssessmentDefensive hardening
CWECWE-79

Description: The components use Vue's v-html directive to render HTML content. While a sanitize() function is called, its implementation is not visible in the provided code. The sanitizeTooltip() function in form-tasks.vue uses regex-based filtering which may be bypassable. Multiple methods construct HTML strings that are rendered via v-html, creating XSS risk if sanitization is insufficient.

Threat Model Context

This is a Node.js library - vulnerabilities affect downstream consumers who use this package.

Changes

  • src/mixins/datatable.js

Behavior Preservation

The change is scoped to 1 file on the vulnerable path; it only tightens handling of untrusted input and leaves valid inputs unaffected.

Security Invariant

Property: User-supplied strings in HTTP responses are HTML-escaped

Regression test
const{ mount }=require('@vue/test-utils');constFormRequests=require('src/components/renderer/form-requests.vue').default;describe("User-supplied strings in HTTP responses are HTML-escaped",()=>{constpayloads=[{input: '<script>alert(1)</script>',description: 'script tag payload'},{input: '<img onerror=alert(1) src=x>',description: 'event handler payload'},{input: '"><svg onload=alert(1)>',description: 'attribute break payload'},{input: 'normal text',description: 'valid input'},{input: '',description: 'empty string boundary'}];test.each(payloads)("sanitizes adversarial input: $description",async({ input })=>{constwrapper=mount(FormRequests,{propsData: {row: {testField: input},header: 'testField'}});// Wait for Vue to renderawaitwrapper.vm.$nextTick();// Get the actual rendered HTMLconstrenderedHtml=wrapper.html();// Check that raw dangerous sequences are not presentexpect(renderedHtml).not.toContain('<script>');expect(renderedHtml).not.toContain('onerror=');expect(renderedHtml).not.toContain('onload=');// Verify the content is properly escaped or sanitized// Either the input should be escaped (contain &lt; etc) or removedif(input.includes('<')){expect(renderedHtml).toMatch(/&lt;|&#x3C;/);}// Verify v-html directive is not rendering raw dangerous HTMLconstspanElement=wrapper.find('span');expect(spanElement.exists()).toBe(true);// Check that inner HTML doesn't contain unescaped dangerous tagsconstinnerHtml=spanElement.element.innerHTML;constdangerousPatterns=[/<script/i,/onerror=/i,/onload=/i];dangerousPatterns.forEach(pattern=>{expect(innerHtml).not.toMatch(pattern);});});});

This test guards against regressions — it's useful independent of the code change above.


This patch removes an exploit primitive — a code pattern that, while not independently exploitable today, could be chained with other weaknesses by automated exploit-development tooling. Proactive removal of such primitives raises the bar against increasingly capable automated attack tools.


Automated security fix by OrbisAI Security

Automated security fix generated by OrbisAI Security
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@anupamme