Skip to content

Reflected XSS in the OAuth callback and stored XSS in the Sparks feed #4

Description

@EnesYilmazcode

Two injection points.

Reflected, backend/server.js:505: values from the OAuth callback are interpolated into an inline <script> without escaping, so a crafted callback URL executes attacker script on your origin, with access to the signed-in Firebase session.

Stored, dashboard.html:1116: spark.thumbnail and spark.id are interpolated into innerHTML unescaped. Because any signed-in user can create a spark, one user can store script that runs in every other user's browser when the feed renders.

Should be

  • Never interpolate untrusted values into an inline script. Pass data via JSON.stringify into a <script type="application/json"> block and read it with textContent, or set values from a same-origin fetch.
  • Use textContent and createElement for the feed instead of innerHTML, or escape every interpolated field.
  • Consider a Content-Security-Policy header that disallows inline script.

Found in the 2026-08-16 audit (30-agent sweep, 481 findings). Every line reference was verified against main at the time of filing.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P0Broken in production right nowbugSomething isn't workingsecuritySecurity defect

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions