Skip to content

🛡️ Sentinel: [HIGH] Fix XSS in blog rendering and improve JSON-LD security - #66

Open
Simonc44 wants to merge 1 commit into
mainfrom
sentinel-fix-xss-blog-jsonld-8585459100112100438
Open

🛡️ Sentinel: [HIGH] Fix XSS in blog rendering and improve JSON-LD security#66
Simonc44 wants to merge 1 commit into
mainfrom
sentinel-fix-xss-blog-jsonld-8585459100112100438

Conversation

@Simonc44

@Simonc44 Simonc44 commented Jul 4, 2026

Copy link
Copy Markdown
Owner

🚨 Severity: HIGH
💡 Vulnerability: Cross-Site Scripting (XSS) in blog rendering and insecure JSON-LD injection.
🎯 Impact: An attacker could potentially inject malicious scripts through blog content or manipulate JSON-LD metadata to execute XSS in the user's browser.
🔧 Fix:

  • Exported and applied the safeJsonLd utility to properly escape JSON-LD content.
  • Integrated sanitizeText to clean blog content blocks before rendering.
  • Enhanced the Markdown-lite link transformation to only allow http://, https://, internal paths (/), and anchors (#), effectively blocking javascript: and other dangerous protocols.
    ✅ Verification:
  • Verified that pnpm build and pnpm lint pass for the modified files.
  • Visually verified blog rendering with a Playwright script and screenshot.
  • Confirmed that the fix is under 50 lines of intentional changes (excluding imports/exports).

PR created automatically by Jules for task 8585459100112100438 started by @Simonc44

…urity

This PR addresses several XSS vulnerabilities in the blog rendering logic and enhances the security of JSON-LD metadata.

- Exported `safeJsonLd` from `__root.tsx` for wider use.
- Applied `safeJsonLd` to JSON-LD scripts in `blog.$slug.tsx`.
- Sanitized blog content in `blog.$slug.tsx` using `sanitizeText` before rendering.
- Implemented protocol-aware link sanitization in blog content to prevent `javascript:` and other malicious URI schemes while allowing safe internal and external links.

Co-authored-by: Simonc44 <216070312+Simonc44@users.noreply.github.com>
@google-labs-jules

Copy link
Copy Markdown
Contributor

👋 Jules, reporting for duty! I'm here to lend a hand with this pull request.

When you start a review, I'll add a 👀 emoji to each comment to let you know I've read it. I'll focus on feedback directed at me and will do my best to stay out of conversations between you and other bots or reviewers to keep the noise down.

I'll push a commit with your requested changes shortly after. Please note there might be a delay between these steps, but rest assured I'm on the job!

For more direct control, you can switch me to Reactive Mode. When this mode is on, I will only act on comments where you specifically mention me with @jules. You can find this option in the Pull Request section of your global Jules UI settings. You can always switch back!

New to Jules? Learn more at jules.google/docs.


For security, I will only act on instructions from the user who triggered this task.

@vercel

vercel Bot commented Jul 4, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
mandat Ready Ready Preview, Comment Jul 4, 2026 4:11am

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant