Skip to content

Commit 5a88e96

Browse files
boutellmyovchevBoDonkeyharounThomas Boutell
authored
Latest security q2 (#5464)
* Bump CLI dependencies (#5383) * Fix choices IDs (#5379) * Fix choices IDs * Cleanup dots from ID values * Update changelog Co-authored-by: Robert Means <robert@apostrophecms.com> --------- Co-authored-by: Robert Means <robert@apostrophecms.com> * Native browser shortcuts work again (#5384) * Pro 8838 charset (#5385) * Removes encoding option and comments hardcoded encoding meta * add changeset * Response to first comments * Log aposResponse errors (#5386) * log aposResponse errors * add changeset --------- Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> * merge back the thanks (#5388) * Postgres (#5365) * postgres experimental WIP * astonishingly, all mocha tests of apostrophe pass with this * mocha tests pass, actual sites work * lint clean * listDatabases support, but changes are coming * wip * dump and restore updates * backpressure, adequate handling of ObjectId for our needs (becomes its hex representation) * mild performance optimization * profiling * testing issue resolved * refactored to db-connect module, introduced sqlite adapter * sqlite WIP * debugging * programmatic API for dump/restore/copy dbs * linting, documentation * MIT license * text ranking is more accurate, documentation is more complete * good full text search for sqlite * updates for compatibility with the rest of the public and private modules, plus a few fixes to genuinely ambiguous tests * requirements found by testing private modules * fixes from full cypress run * eslint passing * restore permissions * maximize atomicity * bug fixes * * exit properly when asset tests fail * "npm test" tests all three adapters * ignore claude-tools in eslint * postgres and sqlite-inclusive ci matrix attempt * clean up logs * We hit github's limit on total configurations because every package gets its own matrix. Solve that with grouping: * apostrophe core * All regular ecosystem packages other than core * non-database-requiring packges * mongodb-specific packages This will probably speed it up too because it won't have to spin up a container a bazillion times. * hardened the asset tests, made them less timing sensitive, fixed a bad commit resulting from the way they dodgily patch themselves without a robust cleanup mechanism * fix a root cause of asset test instability * log mess * implemented missing $size operator * test compatibility * advanced permission uses regex in $in * regex in $in * .db() should not make false promises in plain postgres mode, it should fail * ability to specify a default adapter * obsolete file * put escapeHost back where it belongs * dead code removal, test cleanup * emulate-mongo-3-driver only needed in db-connect * no claude logs in repo (tools are welcome) * * shared aggregation implementation, other shared things * optimize $match when it is the first step in aggregation, don't fetch the whole collection 😜 * multipostgres listDatabases() and .db() should return and expect "fully qualified virtual database names," e.g. physical_db_name-schemaname * vanilla postgres should not attempt to use .db() with alternate names in tests * documentation corrections * documentation errors * listDatabases and documentation corrections * more edge cases revealed by latest work from Miro * anchored prefix regexps are optimized documentation improvements * * matchesQuery in the aggregation cursor implementation doesn't throw on unrecognized operators. It should, and it should support the same mongodb operators that the regular find() path does in postgres/sqlite (our official subset), unless there is an extraordinary reason not to. * Similarly, the main query implementation for normal queries should throw on unrecognized operators if it doesn't already. * The dump/restore programmatic APIs in db-connect concern me. These involve returning the entire database as a string, which could exhaust memory. This impacts both utilities and also copyDatabase(). Could these APIs return and expect async iterators instead of strings? * The test "anchored regex on an indexed field uses a btree index search" runs explain on a query that's hardcoded in the test. Instead these SQL based adapters should expose a means to get the SQL for a query, so it can be directly tested. Otherwise this test proves nothing as changes to the adapter accumulate in future. * Why is this test searching for "at least 1" and not exactly 1? it('should find documents with null value', async function() { const docs = await db.collection('test').find({ value: null }).toArray(); // MongoDB matches both null and missing fields with { value: null } expect(docs.length).to.be.at.least(1); }); * What is the maximum size of a db-connect document in the postgres and sqlite adapters? * Update the copyright year in db-connect/LICENSE.md to 2025. * The db-connect README mentions: sqlite://:memory: What happens if you try to use .db('some-name') with that? I think it would be best to just not support throwaway in-memory sqlite databases because I doubt anyone would intentionally store a website in one. * do not swallow dump/restore errors on indexes * cover how to run the utilities * fix detection of source * separate sanitization for index names * regex prefix safety * pnpm --------- Co-authored-by: Thomas Boutell <boutell@vcs.trox.local> * forgot to include a changeset (#5390) * ignore inline table array as draggable ui for windows (#5392) * Layout focus orchestration (#5393) * Pro 9405 remove hreflang (#5395) * Remove hreflang generation and update README * Add changeset * Changeset update * Pro 9406 base url (#5396) * Removes `seoSiteCanonicalUrl` * Update tests and remove missed log * Change semver level * Bump dependencies (#5398) * Bump dependencies * Fix missing test await resulting in random failures * Pro 9405 remove hreflang (#5395) * Remove hreflang generation and update README * Add changeset * Changeset update * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) (#5400) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) * allow newer twitter domain * infogr.am still around * facebook no longer does oembed * Layout editable gap (#5397) * a11y fixes (#5401) * clarifications (#5403) * Merge commit from fork * Security: a malicious full name containing HTML was executed as HTML in the tooltip displayed with an "i" icon next to the title of the current page, creating an XSS attack risk versus other users. Since most projects permit users to change their full name (the "title" property), All projects with multiple users should be updated promptly to close this vulnerability. * changeset * Merge commit from fork * fix xmp tag vulnerability * thanks * Merge commit from fork * secure the link URL field of image widgets * credit * Merge commit from fork * Merge commit from fork * Merge commit from fork * Fixed arbitrary image URL import vulnerability in rich text impport API * additional reporter * mergeback (#5409) * Latest merge prerelease 2026 05 (#5404) * Fix choices IDs (#5379) * Fix choices IDs * Cleanup dots from ID values * Update changelog Co-authored-by: Robert Means <robert@apostrophecms.com> --------- Co-authored-by: Robert Means <robert@apostrophecms.com> (cherry picked from commit 9f458b5) * Bump CLI dependencies (#5383) (cherry picked from commit a5e1a4a) * Native browser shortcuts work again (#5384) (cherry picked from commit b9b32bd) * Pro 8838 charset (#5385) * Removes encoding option and comments hardcoded encoding meta * add changeset * Response to first comments (cherry picked from commit 08845c5) * Log aposResponse errors (#5386) * log aposResponse errors * add changeset --------- Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> (cherry picked from commit d45e27f) * merge back the thanks (#5388) (cherry picked from commit f3501f4) * ignore inline table array as draggable ui for windows (#5392) (cherry picked from commit b360b05) * Layout focus orchestration (#5393) (cherry picked from commit 77a2968) * Bump dependencies (#5398) * Bump dependencies * Fix missing test await resulting in random failures (cherry picked from commit 008417f) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) (#5400) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) * allow newer twitter domain * infogr.am still around * facebook no longer does oembed (cherry picked from commit e9b3bac) * Layout editable gap (#5397) (cherry picked from commit bc8f7be) * a11y fixes (#5401) (cherry picked from commit 2e2f3b4) * clarifications (#5403) (cherry picked from commit 13f2c69) --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com> * Latest security merge (#5407) * Merge commit from fork * Fixed arbitrary image URL import vulnerability in rich text impport API * additional reporter * Merge commit from fork * Merge commit from fork * Merge commit from fork * secure the link URL field of image widgets * credit * Merge commit from fork * fix xmp tag vulnerability * thanks * Merge commit from fork * Security: a malicious full name containing HTML was executed as HTML in the tooltip displayed with an "i" icon next to the title of the current page, creating an XSS attack risk versus other users. Since most projects permit users to change their full name (the "title" property), All projects with multiple users should be updated promptly to close this vulnerability. * changeset * release only (changelogs formatted) (#5408) --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com> * mergeback (#5414) * Latest merge prerelease 2026 05 (#5404) * Fix choices IDs (#5379) * Fix choices IDs * Cleanup dots from ID values * Update changelog Co-authored-by: Robert Means <robert@apostrophecms.com> --------- Co-authored-by: Robert Means <robert@apostrophecms.com> (cherry picked from commit 9f458b5) * Bump CLI dependencies (#5383) (cherry picked from commit a5e1a4a) * Native browser shortcuts work again (#5384) (cherry picked from commit b9b32bd) * Pro 8838 charset (#5385) * Removes encoding option and comments hardcoded encoding meta * add changeset * Response to first comments (cherry picked from commit 08845c5) * Log aposResponse errors (#5386) * log aposResponse errors * add changeset --------- Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> (cherry picked from commit d45e27f) * merge back the thanks (#5388) (cherry picked from commit f3501f4) * ignore inline table array as draggable ui for windows (#5392) (cherry picked from commit b360b05) * Layout focus orchestration (#5393) (cherry picked from commit 77a2968) * Bump dependencies (#5398) * Bump dependencies * Fix missing test await resulting in random failures (cherry picked from commit 008417f) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) (#5400) * PRO-9467: remove defunct and nonpublic oembed providers and improve developer control to ensure security in the future (no risk exists today) * allow newer twitter domain * infogr.am still around * facebook no longer does oembed (cherry picked from commit e9b3bac) * Layout editable gap (#5397) (cherry picked from commit bc8f7be) * a11y fixes (#5401) (cherry picked from commit 2e2f3b4) * clarifications (#5403) (cherry picked from commit 13f2c69) --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com> * Latest security merge (#5407) * Merge commit from fork * Fixed arbitrary image URL import vulnerability in rich text impport API * additional reporter * Merge commit from fork * Merge commit from fork * Merge commit from fork * secure the link URL field of image widgets * credit * Merge commit from fork * fix xmp tag vulnerability * thanks * Merge commit from fork * Security: a malicious full name containing HTML was executed as HTML in the tooltip displayed with an "i" icon next to the title of the current page, creating an XSS attack risk versus other users. Since most projects permit users to change their full name (the "title" property), All projects with multiple users should be updated promptly to close this vulnerability. * changeset * release only (changelogs formatted) (#5408) * allow oembetter to be released (#5412) * release oembetter 1.2.0 (#5413) * release oembetter 1.2.0 * left commit --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com> * Fix focus trap on the last element in a modal (#5406) * Fix focus trap on the last element in a modal * Fix trap escaping edge cases * Fix import-export noise (#5399) * remove noise, switch to utils debug * Fix tests * Introduce debug option * changelog * Fix test sorting issue * A11y fixes part 3 (#5416) * Fix editor modal a11y issues * Fix manager a11y problems * Fix page manager a11y problems * fix media manager a11y issues * fix a11y issues in style editor and user settings * Fix login a11y issues * eliminate a modal issue * Remove bad aria in rich text * Fix wrong aria in layout * changelog * Fix totp a11y issues, doc context state safety * Fix uncaught error - popup blockers/tests * Fix initial focus trap issue, introduced with recent changes (#5426) * PRO-9542: fix the bug that breaks sitemaps for RA (#5433) * PRO-9542: fix the bug that breaks sitemaps for RA * see changeset * Feature/prevent infinite redirects (#5429) * log aposResponse errors * add changeset * prevent infinite redirects to external URLs --------- Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> * add draggable: false support to non-inline array field (#5435) * add draggable: false support to non-inline array field * Add changeset * Make logged-in cookie name configurable via options (#5430) The logged-in cookie name was hardcoded as 'loggedIn' with TODO comments indicating it should be configurable. This is needed for deployments where multiple Apostrophe instances share a domain (e.g., staging and production on subpaths) and need distinct cookie names to avoid conflicts. Changes: - Added 'loggedInCookieName' option to the login module (defaults to 'loggedIn' for backward compatibility) - Replaced all hardcoded references with self.loggedInCookieName - Removed the TODO comments Usage: modules: { '@apostrophecms/login': { options: { loggedInCookieName: 'myAppLoggedIn' } } } Addresses the TODO comments: 'get cookie name from config' Co-authored-by: Vangalla, Rohith <rohith.vangalla@optum.com> * Revert "Make logged-in cookie name configurable via options (#5430)" (#5436) This reverts commit ddcdaa7. * Feature create-apostrophe (#5425) * Fix new schema areas in existing documents (Astro) (#5434) * Fix orphan or new-in-the-schema areas in external front-ends * Save missing empty areas in the DB, refactor nunjucks path * PRO-6295: jsx as an optional alternative to nunjucks (#5391) * jsx as an optional alternative to nunjucks * eslint, all tests pass * log a useful stack trace on attachment errors! Holy shit! * fix lint * clarify behavior * more tests pass linter * This is just a unit test, but it can't hurt to be thorough & satisfy github-advanced-security Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> * true access to the apos object in jsx, per the spec * more test coverage, no code changes * fix watchers --------- Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> * no watch in prod (#5439) * Fix new schema areas in existing documents (Astro) Part II (#5440) * Prevent data corruption when stubbing areas for Astro * Fix false positive orphan area warnings * Guard against corrupt area items * Fix raw-text sanitization bypass vulnerability and add regression tests (#5432) * changeset for singh contribution (#5442) * Fix relationship select scrolling issue (#5445) * Fix relationship select scrolling issue * Prevent same scrolling bugs to appear in media manager * jsx changeset (#5446) * Ensure install of the project root for astro projects (#5449) * test node 26 (#5450) * test node 26 * support node 26 by bumping the better-sqlite3 version * node 22 requirement * Add link for telemetry policy (#5455) * remove absent options (#5456) * Remove consumed 4.30.0 changesets from main (#5454) * cli links that are correct, or will be post publish (#5458) * release db connect to solve chicken and egg problem in cypress-tools (#5459) * Corrects documentation links (#5457) * Corrects documentation links * correct `guides` -> `guide` * Merge commit from fork * Merge commit from fork * Merge commit from fork * Merge commit from fork * Security: added a number of new attributes to be protected against unsafe URLs, e.g. javascript: and similar. None of these are used in the default configuration of sanitize-html or apostrophe or likely to be used there, and some attributes, like an action for a form, are inherently unsafe to allow if XSS protection is your goal. Nevertheless it makes sense to block certain URL types where they are not appropriate. Thanks to [crattack](https://github.com/crattack) for reporting the vulnerability. * changeset * removed duplicate changeset * patch the right module --------- Co-authored-by: Miro Yovchev <2827783+myovchev@users.noreply.github.com> Co-authored-by: Robert Means <robert@apostrophecms.com> Co-authored-by: haroun <1765606+haroun@users.noreply.github.com> Co-authored-by: Harouna Traoré <haroun@users.noreply.github.com> Co-authored-by: Thomas Boutell <boutell@vcs.trox.local> Co-authored-by: Stuart Romanek <stuart@apostrophecms.com> Co-authored-by: RohithVangalla1 <reachrohithv@gmail.com> Co-authored-by: Vangalla, Rohith <rohith.vangalla@optum.com> Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com> Co-authored-by: Dipanshu singh <161134993+Dipanshusinghh@users.noreply.github.com>
1 parent b57cbda commit 5a88e96

13 files changed

Lines changed: 486 additions & 21 deletions

File tree

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"sanitize-html": patch
3+
---
4+
5+
Security: added a number of new attributes to be protected against unsafe URLs, e.g. `javascript:` and similar. None of these are used in the default configuration of `sanitize-html` or `apostrophe` or likely to be used there, and some attributes, like an `action` for a `form`, are inherently unsafe to allow if XSS protection is your goal. Nevertheless it makes sense to block certain URL types where they are not appropriate. Some attributes are not supported at all by modern browsers but are included for completeness. Thanks to [crattack](https://github.com/crattack) for reporting the vulnerability.
Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"apostrophe": patch
3+
---
4+
5+
Security: when `@apostrophecms/file` pretty URLs are enabled (`prettyUrls: true`), the upstream request used to serve the file is no longer built from the incoming `Host` header. The self-request is now resolved against the site's configured `baseUrl` (via `req.baseUrl`), falling back to the request host only when no `baseUrl` is configured. This closes a server-side request forgery (SSRF) vector in which the `Host` header could steer the proxied fetch at another host. The real-world risk was low: the path is constrained to an existing attachment's `/uploads/attachments/<cuid>-<slug>.<ext>`, and cuids are unique and immutable, so any reachable content was already public via the front door. Thanks to [EchoSkorJjj](https://github.com/EchoSkorJjj) for reporting the issue.

‎.changeset/proud-moons-guard.md‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"apostrophe": patch
3+
---
4+
5+
Security fix: server-side prototype pollution (CWE-1321) via dot-notation paths. `apos.util.set()` and `apos.util.get()` now refuse to traverse `__proto__`, `constructor` and `prototype` path segments. Previously an authenticated editor could send a PATCH REST API request whose patch operators (for example `$pullAll` with a key of `__proto__.publicApiProjection`) wrote to `Object.prototype`. A polluted `publicApiProjection` defeated the `publicApiCheck()` authorization gate on piece-type REST endpoints for subsequent unauthenticated requests, for the lifetime of the Node.js process. All users should update. Thanks to [tonghuaroot](https://github.com/tonghuaroot), [H3xV0rT3x](https://github.com/H3xV0rT3x), and [5h1kh4r](https://github.com/5h1kh4r) for reporting the vulnerability.

‎.changeset/seo-analytics-xss.md‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
---
2+
"@apostrophecms/seo": patch
3+
---
4+
5+
Security: the Google Analytics tracking ID (`seoGoogleTrackingId`) and Google Tag Manager ID (`seoGoogleTagManager`) global SEO fields were interpolated directly into the bodies of inline `<script>` tags without escaping. Any user permitted to edit the global document, including editors and contributors (if their submission were approved), could set these fields to a value that broke out of the surrounding script and executed arbitrary JavaScript for every visitor on every page (stored XSS). These values are now emitted as escaped `json` nodes, matching the JSON-LD handling, so they can no longer terminate the `<script>` element or escape the string literal they sit in. All projects using `@apostrophecms/seo` with untrusted editors should upgrade promptly to close this vulnerability. Thanks to [H3xV0rT3x](https://github.com/H3xV0rT3x) and [hibrian827](https://github.com/hibrian827) for reporting the issue.

‎packages/apostrophe/modules/@apostrophecms/file/index.js‎

Lines changed: 9 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -248,14 +248,15 @@ module.exports = {
248248
const uglyUrl = self.apos.attachment.url(file.attachment, {
249249
prettyUrl: false
250250
});
251-
// For relative URLs (local uploadfs, not CDN), resolve
252-
// against the current server's origin so the proxy can
253-
// make the self-request. During static builds
254-
// `attachment.url()` may return only a path.
255-
const proxyUrl = uglyUrl.startsWith('/')
256-
? `${req.protocol}://${req.get('host')}${uglyUrl}`
257-
: uglyUrl;
258-
return await streamProxy(req, proxyUrl, { error: self.apos.util.error });
251+
// `uglyUrl` may be relative (local uploadfs) or absolute
252+
// (S3/CDN). For the relative case `streamProxy` resolves it
253+
// against `req.baseUrl`, which reflects the configured
254+
// `baseUrl` (or locale hostname) and only falls back to the
255+
// request host when the site has none. We deliberately do
256+
// not build the upstream URL from the raw `Host` header
257+
// here, as that is attacker-controlled and would allow the
258+
// self-request to be redirected to an arbitrary host (SSRF).
259+
return await streamProxy(req, uglyUrl, { error: self.apos.util.error });
259260
} catch (e) {
260261
self.apos.util.error('Error in pretty URL route:', e);
261262
return res.status(500).send('error');

‎packages/apostrophe/modules/@apostrophecms/util/index.js‎

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -35,6 +35,13 @@ const util = require('util');
3535
const { stripIndent } = require('common-tags');
3636
const glob = require('../../../lib/glob.js');
3737

38+
// Dot-path segments that must never be traversed when walking a
39+
// user-supplied path in `apos.util.get` and `apos.util.set`. Following any
40+
// of these reaches the prototype chain and enables server-side prototype
41+
// pollution (CWE-1321), e.g. a PATCH `$pullAll` key of
42+
// `__proto__.publicApiProjection`.
43+
const unsafePathSegments = new Set([ '__proto__', 'constructor', 'prototype' ]);
44+
3845
module.exports = {
3946
options: {
4047
alias: 'util',
@@ -755,6 +762,10 @@ module.exports = {
755762
if (o == null) {
756763
return undefined;
757764
}
765+
if (unsafePathSegments.has(p)) {
766+
// Never read through the prototype chain (CWE-1321)
767+
return undefined;
768+
}
758769
o = o[p];
759770
}
760771
}
@@ -819,6 +830,12 @@ module.exports = {
819830
}
820831
}
821832
path = path.split('.');
833+
for (p of path) {
834+
if (unsafePathSegments.has(p)) {
835+
// Refuse to write through the prototype chain (CWE-1321)
836+
throw self.apos.error('invalid', `Unsafe property name "${p}" in dot path`);
837+
}
838+
}
822839
for (i = 0; (i < (path.length - 1)); i++) {
823840
p = path[i];
824841
o = o[p];

‎packages/apostrophe/test/files.js‎

Lines changed: 28 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -132,6 +132,34 @@ describe('Files', function() {
132132
}
133133
});
134134

135+
it('should ignore a spoofed Host header when proxying the pretty URL (SSRF regression)', async function() {
136+
const req = apos.task.getAnonReq();
137+
try {
138+
apos.file.options.prettyUrls = true;
139+
const files = await apos.file.find(req).toArray();
140+
assert.strictEqual(files.length, 1);
141+
const file = files[0];
142+
const attachment = apos.attachment.first(file);
143+
const url = apos.attachment.url(attachment);
144+
assert(url);
145+
// Send an attacker-controlled Host header (e.g. the cloud metadata
146+
// address from the advisory). The upstream fetch must be resolved
147+
// against the server-trusted baseUrl, not this header, so the
148+
// legitimate content is still served and the request is never
149+
// steered at the spoofed host.
150+
const response = await apos.http.get(url, {
151+
headers: {
152+
Host: '169.254.169.254'
153+
},
154+
fullResponse: true
155+
});
156+
assert.strictEqual(response.status, 200);
157+
assert.strictEqual(response.body, attachment.data);
158+
} finally {
159+
apos.file.options.prettyUrls = false;
160+
}
161+
});
162+
135163
});
136164

137165
describe('Files with i18n locale prefixes', function() {

‎packages/apostrophe/test/utils.js‎

Lines changed: 103 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -372,6 +372,109 @@ describe('Utils', async function() {
372372
assert(data.shoes[0].size === 8);
373373
});
374374

375+
// Server-Side Prototype Pollution (CWE-1321) regression coverage.
376+
// apos.util.set and apos.util.get traverse user-supplied dot-notation
377+
// paths. A segment of `__proto__`, `constructor` or `prototype` must
378+
// never be followed, or an authenticated editor could write to
379+
// Object.prototype (for example via the $pullAll patch operator) and
380+
// poison authorization checks process-wide. See GHSA-6h5j-32cf-4253.
381+
382+
it('utils.set must reject a __proto__ segment instead of polluting Object.prototype', function() {
383+
const data = {};
384+
try {
385+
assert.throws(() => {
386+
apos.util.set(data, '__proto__.polluted', 'yes');
387+
}, { name: 'invalid' });
388+
assert.strictEqual({}.polluted, undefined);
389+
assert.strictEqual(data.polluted, undefined);
390+
} finally {
391+
// Belt and suspenders: if the guard ever regresses, do not leak a
392+
// polluted prototype into the rest of the suite.
393+
delete Object.prototype.polluted;
394+
}
395+
});
396+
397+
it('utils.set must reject a constructor.prototype segment', function() {
398+
const data = {};
399+
try {
400+
assert.throws(() => {
401+
apos.util.set(data, 'constructor.prototype.polluted', 'yes');
402+
}, { name: 'invalid' });
403+
assert.strictEqual({}.polluted, undefined);
404+
} finally {
405+
delete Object.prototype.polluted;
406+
}
407+
});
408+
409+
it('utils.set must reject a trailing __proto__ segment rather than replacing the prototype', function() {
410+
const data = {};
411+
assert.throws(() => {
412+
apos.util.set(data, '__proto__', { polluted: 'yes' });
413+
}, { name: 'invalid' });
414+
assert.strictEqual(Object.getPrototypeOf(data), Object.prototype);
415+
assert.strictEqual(data.polluted, undefined);
416+
});
417+
418+
it('utils.set must reject a dangerous segment exposed after an @ reference', function() {
419+
const data = {
420+
items: [
421+
{
422+
_id: 'abc',
423+
sub: {}
424+
}
425+
]
426+
};
427+
try {
428+
assert.throws(() => {
429+
apos.util.set(data, '@abc.__proto__.polluted', 'yes');
430+
}, { name: 'invalid' });
431+
assert.strictEqual({}.polluted, undefined);
432+
} finally {
433+
delete Object.prototype.polluted;
434+
}
435+
});
436+
437+
it('utils.get must not traverse into the prototype chain via __proto__', function() {
438+
// Without the guard this returns Object.prototype.toString (a function).
439+
assert.strictEqual(apos.util.get({ a: 1 }, '__proto__.toString'), undefined);
440+
assert.strictEqual(apos.util.get({ a: 1 }, '__proto__'), undefined);
441+
});
442+
443+
it('implementPatchOperators must not let a $pullAll key pollute Object.prototype', function() {
444+
// The reported attack vector: an authenticated editor PATCH body of
445+
// { $pullAll: { '__proto__.publicApiProjection': [] } } reached
446+
// apos.util.set with a fully attacker-controlled key.
447+
const patch = {
448+
$pullAll: {
449+
'__proto__.publicApiProjection': []
450+
}
451+
};
452+
try {
453+
assert.throws(() => {
454+
apos.schema.implementPatchOperators(patch, {});
455+
}, { name: 'invalid' });
456+
assert.strictEqual({}.publicApiProjection, undefined);
457+
} finally {
458+
delete Object.prototype.publicApiProjection;
459+
}
460+
});
461+
462+
it('implementPatchOperators must not let a direct dot-notation key pollute Object.prototype', function() {
463+
// The second documented entry point: a top-level dotted key whose value
464+
// is fully attacker-controlled.
465+
const patch = {
466+
'__proto__.publicApiProjection': { title: 1 }
467+
};
468+
try {
469+
assert.throws(() => {
470+
apos.schema.implementPatchOperators(patch, {});
471+
}, { name: 'invalid' });
472+
assert.strictEqual({}.publicApiProjection, undefined);
473+
} finally {
474+
delete Object.prototype.publicApiProjection;
475+
}
476+
});
477+
375478
it('should slugify', function () {
376479
// Basic
377480
assert.equal(

‎packages/sanitize-html/README.md‎

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -182,7 +182,14 @@ selfClosing: [ 'img', 'br', 'hr', 'area', 'base', 'basefont', 'input', 'link', '
182182
// URL schemes we permit
183183
allowedSchemes: [ 'http', 'https', 'ftp', 'mailto', 'tel' ],
184184
allowedSchemesByTag: {},
185-
allowedSchemesAppliedToAttributes: [ 'href', 'src', 'cite' ],
185+
allowedSchemesAppliedToAttributes: [
186+
'href', 'src', 'cite',
187+
'action', 'formaction', 'data', 'xlink:href',
188+
'poster', 'background', 'ping',
189+
'longdesc', 'usemap', 'codebase', 'classid', 'archive',
190+
'profile', 'manifest', 'itemid',
191+
'dynsrc', 'lowsrc'
192+
],
186193
allowProtocolRelative: true,
187194
enforceHtmlBoundary: false,
188195
parseStyleAttributes: true

‎packages/sanitize-html/index.js‎

Lines changed: 10 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -440,11 +440,11 @@ function sanitizeHtml(html, options, _recursing) {
440440
return;
441441
}
442442
}
443-
if (a === 'srcset') {
443+
if (a === 'srcset' || a === 'imagesrcset') {
444444
try {
445445
let parsed = parseSrcset(value);
446446
parsed.forEach(function(value) {
447-
if (naughtyHref('srcset', value.url)) {
447+
if (naughtyHref(a, value.url)) {
448448
value.evil = true;
449449
}
450450
});
@@ -957,7 +957,14 @@ sanitizeHtml.defaults = {
957957
// URL schemes we permit
958958
allowedSchemes: [ 'http', 'https', 'ftp', 'mailto', 'tel' ],
959959
allowedSchemesByTag: {},
960-
allowedSchemesAppliedToAttributes: [ 'href', 'src', 'cite' ],
960+
allowedSchemesAppliedToAttributes: [
961+
'href', 'src', 'cite',
962+
'action', 'formaction', 'data', 'xlink:href',
963+
'poster', 'background', 'ping',
964+
'longdesc', 'usemap', 'codebase', 'classid', 'archive',
965+
'profile', 'manifest', 'itemid',
966+
'dynsrc', 'lowsrc'
967+
],
961968
allowProtocolRelative: true,
962969
enforceHtmlBoundary: false,
963970
parseStyleAttributes: true,

0 commit comments

Comments
 (0)