🟡 [P1] Add input sanitization on user-controlled fields #285

Closed
opened 2026-02-03 22:30:07 +00:00 by jason.woltje · 0 comments
Owner

Summary

User input validated for type but not sanitized for XSS or special characters.

Vulnerable Fields

  • Connection metadata
  • Identity linking metadata
  • Rejection/disconnect reasons
  • Command payloads

Required Fix

Use class-sanitizer or manual sanitization.

Priority

HIGH (P1) - XSS risk

## Summary User input validated for type but not sanitized for XSS or special characters. ## Vulnerable Fields - Connection metadata - Identity linking metadata - Rejection/disconnect reasons - Command payloads ## Required Fix Use `class-sanitizer` or manual sanitization. ## Priority **HIGH (P1)** - XSS risk
jason.woltje added the securitywebp1 labels 2026-02-03 22:30:07 +00:00
jason.woltje added this to the M7.1-Remediation (0.0.8) milestone 2026-02-03 22:31:34 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: mosaic/stack#285