🔒 Fix XSS vulnerability in dashboard console using DOMPurify - #26
Conversation
Mitigated a Cross-Site Scripting (XSS) vulnerability in `dashboard/src/components/nv-console.ts` where unescaped `consoleLines` messages were directly appended via `.innerHTML`. Added `dompurify` to sanitize log contents before rendering them, preventing malicious script execution in the client browser. Co-authored-by: manupawickramasinghe <73810867+manupawickramasinghe@users.noreply.github.com>
|
👋 Jules, reporting for duty! I'm here to lend a hand with this pull request. When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down. I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job! For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with New to Jules? Learn more at jules.google/docs. For security, I will only act on instructions from the user who triggered this task. |
🎯 What:
Fixed a Cross-Site Scripting (XSS) vulnerability in the dashboard console component (
dashboard/src/components/nv-console.ts). Log messages were being directly rendered to the DOM using.innerHTMLwithout any sanitization.If any unsanitized user input or unvalidated external data from the transport/WebSocket layer were printed to the dashboard logs, it could be executed as arbitrary JavaScript in the user's browser, leading to session hijacking, data exfiltration, or unauthorized actions within the dashboard context.
🛡️ Solution:
dompurifylibrary and its corresponding TypeScript typings to thedashboarddependencies.l.msginterpolation insideDOMPurify.sanitize()prior to assignment to.innerHTML.PR created automatically by Jules for task 5282015801771388990 started by @manupawickramasinghe