Repository navigation
fix(security): treat MDX expression braces as active content - #676
Closed
hivecommons-hive[bot] wants to merge 1 commit into
Closed
hivecommons-hive[bot] wants to merge 1 commit into
hivecommons-hive[bot] wants to merge 1 commit into
Conversation
The imported-page gate reported disallowed elements, event handlers, script-capable URL schemes and unexpected ESM statements, but never modelled the one MDX construct that is JavaScript by definition: a braced expression. Docusaurus compiles docs/architectures/*.md as MDX, and those bodies are written verbatim from a third-party repository, so upstream text could ship arbitrary script into the published origin. Flag every remaining brace after code spans and fences are blanked, allowing only the inert string-literal attribute form the importer emits itself. Only the braces of that form are neutralized, so a script URI smuggled into a prop value is still reported. Signed-off-by: sec-check <sec-check@hive.kubestellar.io>
Contributor
Author
|
Important Held for human review by the hive's ACMM level gate. This PR was opened by the "sec-check" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the Hive will automatically remove the |
This was referenced Sep 25, 2026
Member
|
Superseded by #753, which consolidates the six open security-fix PRs (commits cherry-picked unmodified, authorship and DCO preserved). |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Security Fix
Closes the MDX-expression bypass in the imported-page active-content gate.
Claims exactly two files:
scripts/lib/mdx-active-content.mjs(thefindActiveContentscanner) and its test filetests/mdx-active-content.test.mjs.No other script, validator, workflow or data file is touched, and no
package.jsonscript is changed.The gap
findActiveContent()reported disallowed elements, event handler attributes,script-capable URL schemes and unexpected ESM statements, but had no check for
{ ... }— the one MDX construct that is JavaScript by definition. Becausedocs/architectures/*.mdis written verbatim fromcncf/architectureby theunattended daily import, and Docusaurus 3.10.2 compiles
.mdas MDX (nomarkdown.formatoverride indocusaurus.config.js), upstream text could shiparbitrary script into the published site origin.
cleanMarkdown()escapes<>but leaves braces alone.
The change
After code spans and fences are blanked (MDX evaluates neither), every
remaining
{is a finding, with one narrow allowance: thename={"json string"}attribute form thatscripts/lib/jsx-attributes.mjsemits. Anexpression whose entire body is a single string literal evaluates to that
string and has no call, member access or identifier reference available to it,
so it is inert wherever it appears. The pattern requires the closing brace to
follow the closing quote immediately, so
{"a" + fetch(x)}does not match.Only the braces of the allowed form are neutralized — the quoted value stays in
place, so
href={"javascript:alert(1)"}is still reported as a script-capableURL scheme rather than hidden by the allowance. Replacement is one space per
brace, keeping line lengths stable so findings keep accurate line numbers.
The check is deliberately fail-closed: literal braces in upstream prose are
reported rather than assumed harmless. All nine currently imported bodies
contain no braces outside generated card markup, so this costs nothing today.
Verification at this branch head
The payload is now rejected by the check CI already runs on every PR:
Real repository content is unaffected, and the full suite and coverage gate pass:
Seven new tests cover the executable forms, a multi-line expression, the
allowed string-literal attribute, an attribute expression that is more than a
literal, the value still being scanned inside an allowance, and braces in code.
One existing assertion changed:
hi` `` now reportsthe handler and the expression it is bound through, which is correct.
Related Issue
Closes #675
Filed by sec-check agent (ACMM L4/L5 — hold-gated mode). Hold-gated: human review required.
— hive: agent=sec-check backend=copilot model=claude-opus-5 copilot=1.0.88