Skip to content

Commit f74cccd

Browse files
SkyZeroZxalan-agius4
authored andcommitted
fixup! fix: Escapes </noscript in raw text when scripting enabled
1 parent 33fb135 commit f74cccd

2 files changed

Lines changed: 4 additions & 7 deletions

File tree

‎lib/NodeUtils.js‎

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -29,6 +29,7 @@ var hasRawContent = {
2929
XMP: true,
3030
IFRAME: true,
3131
NOEMBED: true,
32+
NOSCRIPT: true,
3233
NOFRAMES: true,
3334
PLAINTEXT: true
3435
};
@@ -195,8 +196,7 @@ function serializeOne(kid, parent) {
195196
// If an element can have raw content, this content may
196197
// potentially require escaping to avoid XSS.
197198
var upperTag = tagname.toUpperCase();
198-
if (hasRawContent[upperTag] ||
199-
(upperTag === 'NOSCRIPT' && kid.ownerDocument._scripting_enabled)) {
199+
if (hasRawContent[upperTag]) {
200200
ss = escapeMatchingClosingTag(ss, tagname);
201201
}
202202
if (html && extraNewLine[tagname] && ss.charAt(0)==='\n') s += '\n';
@@ -214,8 +214,7 @@ function serializeOne(kid, parent) {
214214
else
215215
parenttag = '';
216216

217-
if (hasRawContent[parenttag] ||
218-
(parenttag==='NOSCRIPT' && parent.ownerDocument._scripting_enabled)) {
217+
if (hasRawContent[parenttag]) {
219218
s += kid.data;
220219
} else {
221220
s += escape(kid.data);

‎test/xss.js‎

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -180,13 +180,11 @@ exports.styleMatchingClosingTagSkipsUnclosedCommentedContent = function () {
180180
};
181181

182182
exports.noscriptMatchingClosingTagInRawText = function () {
183-
// Use a parsed document so `_scripting_enabled` is true, matching how
184-
// Angular SSR / platform-server uses domino. With scripting enabled,
185183
// <noscript> is a raw-text element on serialization and its text data
186184
// must have any `</noscript` closing-tag prefix escaped, otherwise an
187185
// attacker-controlled text payload can break out and inject a live
188186
// <script> sibling in the receiving browser.
189-
const document = domino.createDocument('<!doctype html><html><body></body></html>');
187+
const document = domino.createDocument('');
190188
const noscript = document.createElement('noscript');
191189
noscript.textContent = 'abc</noscript><script>alert(1)</script>';
192190
document.body.appendChild(noscript);

0 commit comments

Comments
 (0)