Pull Request Overview
- Opened on July 16, 2026
- Status Closed
- Commit count 1 with first commit July 16, 2026
Total Delta
Open Days
Test Delta
How long has this pull request spent in each phase of its lifecycle?
| Fraction of total time | Business days | Phase |
|---|---|---|
|
|
0 days | Authoring 1 commit before pull request opened for review |
|
|
0 days | Awaiting first review |
Total time for pull request 0 business days from first commit to closed PR
Security: Potential XSS via Unsanitized Board Data in settingsAbout.js
Summary
Security: Potential XSS via Unsanitized Board Data in settingsAbout.js
Problem
Severity: Medium | File: js/core/settingsAbout.js:L31
In settingsAbout.js, board data is retrieved via Espruino.Core.Env.getBoardData(), converted to strings, and then rendered into an HTML table using Espruino.Core.HTML.htmlTable(strData). This HTML is injected directly into the DOM using jQuery's .html() method. If the board data contains malicious HTML/JavaScript (e.g., through a manipulated firmware response), it could be executed in the context of the Web IDE, leading to XSS.
Solution
Ensure that Espruino.Core.HTML.htmlTable properly escapes all values being placed into HTML table cells. Use Espruino.Core.Utils.escapeHTML (which is used elsewhere in the same file) on the values before constructing the HTML table.
Changes
-
js/core/settingsAbout.js(modified)
Comments Threads Pending Resolution
Resolved Comment Threads
No resolved comments have been left on this PR.