Skip to content

fix: sanitize markup to prevent XSS - #2603

Merged
hupf merged 5 commits into
mainfrom
fix/security-issues
Oct 5, 2026
Merged

hupf merged 5 commits into
mainfrom
fix/security-issues

Conversation

@mburri

@mburri mburri commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

fixes some possible xxs vulnerabilties

see https://gitlab.lindas.admin.ch/bafu/bafu-visualize/visualize/-/work_items/787 for more details and how to reproduce

@vercel

vercel Bot commented Sep 9, 2026 •

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
visualization-tool Ready Ready Preview Oct 5, 2026 12:36pm UTC

Request Review

}}
dangerouslySetInnerHTML={{ __html: layer.description }}
/>
<CustomLayerDescription description={layer.description} />

@hupf hupf Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@mburri That fixes the XSS issue, but it also breaks every formatting markup. Shouldn't we sanitize the description instead, like we did in other places? Or was there a decision, that no formatting is allowed here?

If formatting should still work, I'd introduce a sanitizing component, maybe leveraging the already present sanitizeSchema/rehypeSanitize? Otherwise DOMPurify would be the goto IMO.

Also, I assume there is another XSS in app/rdf/query-search.ts with the highlightedTitle and highlightedDescription.

@hupf
hupf force-pushed the fix/security-issues branch from 555b1b0 to bb54735 Compare October 5, 2026 11:09
@hupf hupf changed the title fix: xss vulnerabilities fix: sanitize markup to prevent XSS Oct 5, 2026
@hupf
hupf merged commit 814cb42 into main Oct 5, 2026
12 checks passed
@hupf
hupf deleted the fix/security-issues branch October 5, 2026 12:46

This branch was successfully deployed

1 active deployment
Preview — 54d37dcf Deployed Oct 5, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants