Skip to content

πŸ›‘οΈ Sentinel: [CRITICAL] Fix XSS vulnerability in JSON-LD script tags#279

Open
hadsern wants to merge 1 commit into
v2-foundationfrom
sentinel/fix-json-ld-xss-13016380486855987287
Open

πŸ›‘οΈ Sentinel: [CRITICAL] Fix XSS vulnerability in JSON-LD script tags#279
hadsern wants to merge 1 commit into
v2-foundationfrom
sentinel/fix-json-ld-xss-13016380486855987287

Conversation

@hadsern

@hadsern hadsern commented Apr 15, 2026

Copy link
Copy Markdown
Collaborator

🚨 Severity: CRITICAL
πŸ’‘ Vulnerability: JSON.stringify does not automatically escape HTML control characters (<, >, &). The SchemaScript component takes this output and injects it into a <script> tag via dangerouslySetInnerHTML. If any schema strings contain </script><script>alert(1)</script>, the JSON stringification would maintain the < and > characters, allowing an attacker to break out of the JSON-LD script block and execute malicious JavaScript on the client.
🎯 Impact: This allows arbitrary JavaScript execution (XSS) on clients loading pages where schema is generated.
πŸ”§ Fix: Manually string replace < and > with their JSON unicode escape equivalents (\\u003c and \\u003e).
βœ… Verification: pnpm test, pnpm lint, and pnpm build have successfully run. The generated schema JSON output is correctly formatted and escaped.


PR created automatically by Jules for task 13016380486855987287 started by @hadsern

Manually escape HTML control characters like `<` and `>` to prevent an XSS vector when user input is piped to `JSON.stringify` inside of a `dangerouslySetInnerHTML` call within `SchemaScript`.

Co-authored-by: hadsern <5723837+hadsern@users.noreply.github.com>
@google-labs-jules

Copy link
Copy Markdown

πŸ‘‹ Jules, reporting for duty! I'm here to lend a hand with this pull request.

When you start a review, I'll add a πŸ‘€ emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down.

I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job!

For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with @jules. You can find this option in the Pull Request section of your global Jules UI settings. You can always switch back!

New to Jules? Learn more at jules.google/docs.


For security, I will only act on instructions from the user who triggered this task.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant