Skip to content

harden: add output encoding in index.js (CWE-79) - #57

Closed
anupamme wants to merge 1 commit into
pkgjs:mainfrom
anupamme:fix-repo-statusboard-cwe-79-sanitize-issue-url
Closed

anupamme wants to merge 1 commit into
pkgjs:mainfrom
anupamme:fix-repo-statusboard-cwe-79-sanitize-issue-url

Conversation

@anupamme

Copy link
Copy Markdown

The template/js/index.js fetches JSON data from external sources (labeledIssues.json, userActivity.json, projects.json) and renders values directly into the DOM using lit-html templates. While lit-html provides auto-escaping for text content, URL values in href attributes and data flows from untrusted external sources lack validation or sanitization. This is defence-in-depth at template/js/index.js:18 rather than a vulnerability I can show is exploitable here — it makes the failure mode explicit and bounded. Close it freely if the pattern is intentional.

Reference: CWE-79

What changed

  • template/js/index.js

Verification

No automated check could be run against this repository, so this change is unverified beyond review. Please treat it as a suggestion.


Automated security fix by OrbisAI Security

Automated security fix generated by OrbisAI Security

Signed-off-by: anupamme <mediratta@gmail.com>
@bjohansebas

Copy link
Copy Markdown
Member

these data come from the GitHub API, so there’s no risk, and this doesn’t add anything new to the workflow.

@krzysdz

krzysdz commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

I'm pretty sure that issue.url originates from GitHub API (docs) and unless someone hacks GitHub (in which case there would be bigger problems) these are trusted.

I recognise the OrbitAI Security bot - I have closed multiple bad PRs with this signature (in other repos). In case there's a human who reads this: Has this bot ever detected something correctly? Do you think that using a bot to report nonexistent vulnerabilities with no human oversight and ignoring all policies and guidelines of projects the you try to "contribute" to is in any way ethical?

@anupamme

Copy link
Copy Markdown
Author

There is a human in the loop.

Sorry for the noise. We do have a decent merge rate in the PRs we open. You can find out about the PRs which get merged here.

Coming to the PR, I agree that issue.url currently originates from the GitHub API and that I haven’t demonstrated an attacker-controlled path to that value in the existing workflow. So I agree this should not be presented as a confirmed CWE-79 vulnerability. The change was intended as defence-in-depth URL-scheme validation rather than a claim of a demonstrated exploit.

Would you like to opt out of any future security PRs?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants