Category

Cwe 79

Security vulnerabilities and automated fixes for cwe 79 issues

5 posts found

high7 min

escapeQuotes() Gap Lets File Names XSS Search Results

The desktop app's file-search results renderer built HTML strings from file names and paths using only `escapeQuotes()` and `escapeBackSlash()`, which strip quotes and backslashes but leave `<`, `>`, and `&` untouched. A file or folder named with an HTML payload such as `<img src=x onerror=alert(1)>` would execute when the matching search result was rendered, giving an attacker script execution in the app's DOM context.

#xss#cwe-79#output-encoding+3 more
A
anupamme
Sep 25, 2026
critical6 min

How stored XSS happens in TinyMCE plugins and how to fix it

The snippets plugin's `Main.ts` inserted raw, unsanitized snippet content directly into the TinyMCE editor via `editor.insertContent(snippet.content)`, allowing stored JavaScript payloads saved by any snippet editor to execute in every user's browser. The fix routes snippet content through TinyMCE's own parser and serializer before insertion, stripping dangerous markup while preserving legitimate formatting.

#xss#typescript#tinymce+2 more
A
anupamme
Sep 9, 2026
critical5 min

How Cross-Site Scripting (XSS) happens in JavaScript sanitization functions and how to fix it

A critical XSS vulnerability was discovered in the `sanitizeInput()` function in script.js, where only angle brackets were being escaped while quotes, ampersands, and backticks remained unprotected. This incomplete sanitization allowed attackers to craft payloads using event handlers and template literals that bypassed the security controls entirely. The fix implements comprehensive HTML entity encoding for all XSS-relevant characters.

#xss#javascript#input-sanitization+3 more
A
anupamme
Sep 6, 2026
critical9 min

How Cross-Site Scripting (XSS) happens in JavaScript browser extensions and how to fix it

A cross-site scripting (XSS) vulnerability was discovered in `extension/lib/chatgpt.js` where the `chatgpt.alert()` function used `modalMsg.innerText` to set user-controlled content before passing it to `chatgpt.renderHTML()`, allowing injected HTML to be rendered unsanitized. The fix replaces `innerText` with `textContent` and introduces an allowlist of safe HTML tags and attributes inside `renderHTML()`. This prevents attackers from injecting arbitrary HTML or JavaScript through modal message

#xss#javascript#browser-extension+2 more
A
anupamme
Aug 26, 2026
critical8 min

How Cross-Site Scripting (XSS) happens in JavaScript template rendering and how to fix it

A cross-site scripting (XSS) vulnerability in `renderer/views/library.js` allowed attackers who could control mod metadata—such as category icons rendered in pack thumbnail grids—to inject arbitrary JavaScript through unescaped output in `innerHTML` assignments. The fix wraps the `catIcon()` return value in the existing `esc()` helper, ensuring all dynamically generated HTML content is properly encoded before insertion into the DOM.

#xss#javascript#cross-site-scripting+4 more
A
anupamme
Aug 10, 2026