Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Renderer h() sets any known DOM property from props; restrict it before a dynamic key appears

Closed Beginner friendly
#208 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
70/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
typescript
Domain
security

Research direction

Read the property-assignment branch in src/renderer/src/dom.ts and check the trustedHtml guidance in AGENTS.md. Add a unit test for h('div', { innerHTML: '<b>x</b>' }) and verify the call does not set HTML; then run the relevant renderer tests. The issue leaves the choice between an allow-list and a deny-list open, so settle that scope with maintainers.

Written by the indexing model from the issue text.

Description

enhancement priority: low security severity: low

From Finding 4 of the earlier SECURITY-REVIEW.md, checked against the current code on 2026-10-07. Hardening only: not exploitable today.

Problem

h() (src/renderer/src/dom.ts, the key in element && !key.includes('-') branch) assigns any prop that exists on the element as a DOM property. All current call sites use literal prop names. But a future h(tag, { [name]: value }) with a model- or file-derived key could set innerHTML, outerHTML, srcdoc or href and bypass the trustedHtml rule in AGENTS.md. The CSP and Trusted Types would still block script execution.

Proposal

Limit the property branch to an allow-list (value, checked, disabled, className, textContent, …) or refuse a deny-list (innerHTML, outerHTML, srcdoc, formAction, src, href, on*). Add a unit test that h('div', { innerHTML: '<b>x</b>' }) doesn't set HTML.

Dominant language
TypeScript
Stars
2
Forks
2
Avg merge
5h 28m
Merged PRs (30d)
24

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from PierrunoYT/patch

All issues in PierrunoYT/patch

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.