Security: Potential XSS via Unsanitized Board Data in settingsAbout.js #321

Closed
tomaioo opened 11:29am on July 16, 2026 wanted to merge 13 Ξ” into espruino/espruinowebide master from
fix/security/potential-xss-via-unsanitized-board-data
Diff Delta:
13
About 42 Diff Delta/hour
Classified as:  General

tomaioo's Description of Work

Summary

Security: Potential XSS via Unsanitized Board Data in settingsAbout.js

Problem

Severity: Medium | File: js/core/settingsAbout.js:L31

In settingsAbout.js, board data is retrieved via Espruino.Core.Env.getBoardData(), converted to strings, and then rendered into an HTML table using Espruino.Core.HTML.htmlTable(strData). This HTML is injected directly into the DOM using jQuery's .html() method. If the board data contains malicious HTML/JavaScript (e.g., through a manipulated firmware response), it could be executed in the context of the Web IDE, leading to XSS.

Solution

Ensure that Espruino.Core.HTML.htmlTable properly escapes all values being placed into HTML table cells. Use Espruino.Core.Utils.escapeHTML (which is used elsewhere in the same file) on the values before constructing the HTML table.

Changes



  • js/core/settingsAbout.js (modified)

1 total changed file
Loading changes...
Review complete πŸ’ͺ
The diff well is dry.