Renderer h() sets any known DOM property from props; restrict it before a dynamic key appears
Maintainers usually reply within 1 day
Nobody has claimed this yet.
Assessment
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 70/100
- Issue type
- Bug
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- typescript
- Domain
- security
Research direction
Read the property-assignment branch in src/renderer/src/dom.ts and check the trustedHtml guidance in AGENTS.md. Add a unit test for h('div', { innerHTML: '<b>x</b>' }) and verify the call does not set HTML; then run the relevant renderer tests. The issue leaves the choice between an allow-list and a deny-list open, so settle that scope with maintainers.
Written by the indexing model from the issue text.
Description
From Finding 4 of the earlier SECURITY-REVIEW.md, checked against the current code on 2026-10-07. Hardening only: not exploitable today.
Problem
h() (src/renderer/src/dom.ts, the key in element && !key.includes('-') branch) assigns any prop that exists on the element as a DOM property. All current call sites use literal prop names. But a future h(tag, { [name]: value }) with a model- or file-derived key could set innerHTML, outerHTML, srcdoc or href and bypass the trustedHtml rule in AGENTS.md. The CSP and Trusted Types would still block script execution.
Proposal
Limit the property branch to an allow-list (value, checked, disabled, className, textContent, …) or refuse a deny-list (innerHTML, outerHTML, srcdoc, formAction, src, href, on*). Add a unit test that h('div', { innerHTML: '<b>x</b>' }) doesn't set HTML.
- Dominant language
- TypeScript
- Stars
- 2
- Forks
- 2
- Avg merge
- 5h 28m
- Merged PRs (30d)
- 24
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from PierrunoYT/patch
-
enhancement platform: windows priority: low severity: low
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
PierrunoYT/patch#198 ·
Maintainers usually reply within 1 day
-
priority: medium security severity: low
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
PierrunoYT/patch#66 ·
Maintainers usually reply within 1 day
-
bug platform: macos priority: low severity: low tests
Difficulty 3/5 1-2 days Newbie friendliness 56/100
PierrunoYT/patch#218 · 1 comment ·
Maintainers usually reply within 1 day
-
enhancement priority: low security severity: low
Difficulty 4/5 3-5 days Newbie friendliness 55/100
PierrunoYT/patch#211 · 2 comments ·
Maintainers usually reply within 1 day
-
enhancement platform: windows priority: low security severity: low
Difficulty 4/5 3-5 days Newbie friendliness 55/100
PierrunoYT/patch#207 ·
Maintainers usually reply within 1 day
All issues in PierrunoYT/patch
Similar issues
-
Difficulty 1/5 1-3 hours Newbie friendliness 84/100
Maintainers usually reply within 1 day
-
core
Difficulty 2/5 1-3 hours Newbie friendliness 70/100
vectorize-io/hindsight#5457 ·
Maintainers usually reply within 1 day
-
beginner friendly community contributions-welcome good first issue hacktoberfest help wanted testing up-for-grabs
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
Maintainers usually reply within 1 day
-
Difficulty 1/5 Under an hour Newbie friendliness 85/100
lukilabs/beautiful-mermaid#160 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 66/100
rescript-lang/rescript-lang.org#1420 ·
Maintainers usually reply within 2 days