A05: validate the update feed ReleaseUrl scheme #19

Closed
opened 2026-08-13 09:35:05 +00:00 by nalum · 0 comments
Owner

Admin.tsx:2089 renders <a href={update.url}> straight from the update feed's JSON (internal/services/system/update_rpc.go:96, html_url from the configured Gitea feed). A compromised or malicious feed could supply a javascript: URL — React only console-warns on those and still renders them.

Admin-only page and operator-configured feed, so exploitation needs feed compromise.

Fix: server-side scheme check on ReleaseUrl — accept http/https only, drop anything else.


Source: OWASP Top 10 (2025) audit of v1.1.0, 2026-08-13. File references point at the v1.1.0 tree.

`Admin.tsx:2089` renders `<a href={update.url}>` straight from the update feed's JSON (`internal/services/system/update_rpc.go:96`, `html_url` from the configured Gitea feed). A compromised or malicious feed could supply a `javascript:` URL — React only console-warns on those and still renders them. Admin-only page and operator-configured feed, so exploitation needs feed compromise. **Fix**: server-side scheme check on `ReleaseUrl` — accept `http`/`https` only, drop anything else. --- Source: OWASP Top 10 (2025) audit of `v1.1.0`, 2026-08-13. File references point at the `v1.1.0` tree.
nalum added reference refs/tags/v1.1.0 2026-08-13 09:37:48 +00:00
nalum closed this issue 2026-08-13 11:38:08 +00:00
Sign in to join this conversation.
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
eagraiclainne/app#19
No description provided.