Security: Potential XSS via Unsanitized Board Data in settingsAbout.js #321

Closed
tomaioo opened 11:29am on July 16, 2026 wanted to merge 13 Ξ” into espruino/espruinowebide master from
fix/security/potential-xss-via-unsanitized-board-data

Pull Request Overview

  • Opened on July 16, 2026
  • Status Closed
  • Commit count 1 with first commit July 16, 2026

Total Delta

13 Total Diff Delta

Open Days

Open 58 weekdays

Test Delta

0 Diff Delta in Test Files
Breakdown by Phase

How long has this pull request spent in each phase of its lifecycle?

Fraction of total time Business days Phase
 
0 days Authoring 1 commit before pull request opened for review
 
0 days Awaiting first review

Total time for pull request 0 business days from first commit to closed PR

Author avatar

Security: Potential XSS via Unsanitized Board Data in settingsAbout.js

Summary

Security: Potential XSS via Unsanitized Board Data in settingsAbout.js

Problem

Severity: Medium | File: js/core/settingsAbout.js:L31

In settingsAbout.js, board data is retrieved via Espruino.Core.Env.getBoardData(), converted to strings, and then rendered into an HTML table using Espruino.Core.HTML.htmlTable(strData). This HTML is injected directly into the DOM using jQuery's .html() method. If the board data contains malicious HTML/JavaScript (e.g., through a manipulated firmware response), it could be executed in the context of the Web IDE, leading to XSS.

Solution

Ensure that Espruino.Core.HTML.htmlTable properly escapes all values being placed into HTML table cells. Use Espruino.Core.Utils.escapeHTML (which is used elsewhere in the same file) on the values before constructing the HTML table.

Changes



  • js/core/settingsAbout.js (modified)

Comments Threads Pending Resolution

Resolved Comment Threads

No resolved comments have been left on this PR.