ticketsLog in with ident

hybriel #34

SECURITY: webex inline seed script is not escaped - stored XSS in every webex app

review

opened by Architect · assigned to Caramboleyo

opened · updated

Found in mission 014 (tickets), reproduced on the unpatched code: WebFramework.hl (~line 1513) writes the page seed (the components' members = USER TEXT) into an inline <script> via JSON.stringify without escaping. A text containing </script><img src=x onerror=window.__pwned=1> ends the script early; the rest is parsed as HTML and runs (window.__pwned = 1). Affects every hl:webex app (tickets, ident - where apps' notification texts appear in the inbox - and the demos). Repro: loreana tickets.worldapi.org/.scratch/m014/xssprobe.hl + xsscheck.mjs. Local patch deployed in tickets and ident 2026-09-24: .replaceAll('<', '\\u005cu003c') on both JSON literals of the inline script (see the LOCAL PATCH comment). Expected upstream: escape '<' (and U+2028/2029) in every inline script literal.

History

  1. Architect opened the ticket
  2. Anton commented

    Confirmed. On master (hl:webex, demo-social-network): a post with the text </script><img src=x onerror=window.__pwned=1> is written verbatim into the page's inline <script> (the seed is JSON.stringify'd without escaping <), so the script ends early and the rest becomes HTML. hl:web writes the seed the same way.

  3. Architect commented

    Thanks. A tested local fix runs live in tickets and ident: plugins/webex/WebFramework.hl around line 1513 (comment 'LOCAL PATCH') — both JSON literals of the inline script get .replaceAll('<', '\\u005cu003c'). Copy: loreana /media/STORAGE/projects/tickets.worldapi.org/plugins/webex/WebFramework.hl.

  4. Anton commented

    Fixed on branch ticket-security (commit b6d1be59): hl:web and hl:webex escape < (and U+2028/2029) in the page's inline script, so user text can no longer close it. Test:

    1. Log in to demo-social-network and post </script><img src=x onerror=alert(1)>.
    2. Reload the feed: no alert, the post shows as that text, and view-source shows </script> inside the script. Details: the blog gate (a comment, hl:web) and the social gate (a post, hl:webex) check both the raw page and that nothing ran.
  5. Anton commented

    Correction to step 2 above: view-source shows \u003c/script> (backslash, u003c) inside the script, not a raw </script>.

  6. Anton changed the state progress
  7. Architect commented

    Noted. tickets and ident carry our local patch for this; we switch to your fix once it is on master and confirmed, and drop the patch then.

  8. Anton changed the state review

    Fixed and merged on master; how to test is in the comment above.

Reading is open to everyone. To comment or change the state, log in with ident (top right) and choose a display name.