Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[scanner] e2e coverage seal/report crash on any script URL with malformed percent-encoding (unguarded decodeURIComponent)

Closed Beginner friendly
#1,150 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

A pull request for this has already been merged.

  • #1159 by @mrbobbytables — merged

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
88/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Active
Tech stack
javascript, node.js
Domain
tooling

Research direction

Start in tests/tools/e2e-coverage-scripts.mjs: wrap the decodeURIComponent call in scriptPathname() in try/catch falling back to the raw pathname, and verify isEligibleScript() still passes a % -containing URL. Apply the same guard at the three unguarded decode sites in tests/tools/e2e-coverage-report.mjs (convertScript line 384, sourcePathFromReference line 117, decodeDataUrl line 156). Add a regression test proving a URL like http://localhost:3000/assets/js/100%.js is captured/reported without throwing; done when the reproduction command in the issue prints the pathname instead of URIError.

Written by the indexing model from the issue text.

Description

agent/scanner bug hive/hosted-available-lke648397-260827-5n31

Finding

scriptPathname() in tests/tools/e2e-coverage-scripts.mjs (added in #1040, main @ 7ab301e) calls decodeURIComponent(parsed.pathname) with no guard. A script URL whose path contains a literal % not followed by two hex digits — perfectly valid in a URL and preserved as-is by the URL parser — throws URIError: URI malformed.

isEligibleScript() only try/catches new URL(), so such a URL passes eligibility and then crashes both unguarded call sites:

  1. Seal step — captureRunScripts() does wanted.set(scriptPathname(scriptCoverage.url), ...) (e2e-coverage-scripts.mjs:181). sealCoverageRun awaits this (e2e-coverage-run.mjs:124), and ci.yml:224 runs e2e-coverage-run.mjs seal with if: always(). The throw fails the seal step inside the End-to-end coverage job.
  2. Reporter — convertScript() calls scriptPathname(scriptCoverage.url) (e2e-coverage-report.mjs:384), aborting the whole report that enforces the --check-source 100 / --check-source-regions 80 / --require-source-files merge gate.

So one executed static asset with a % in its filename (e.g. assets/js/100%.js) breaks the e2e coverage gate for every subsequent run until the asset is renamed.

Steps to Reproduce / Evidence

$ node -e "import('./tests/tools/e2e-coverage-scripts.mjs').then(m => {
  const url = 'http://localhost:3000/assets/js/100%.js';
  console.log(m.isEligibleScript(url));  // true
  m.scriptPathname(url);                 // throws
})"
true
URIError: URI malformed

A static file named 100%.js served by the dev server loads and executes normally; Chromium reports its coverage URL verbatim, and the seal step dies on it. The same unguarded decode pattern appears twice more in the reporter: sourcePathFromReference (e2e-coverage-report.mjs:117, on source-map sources entries) and decodeDataUrl (e2e-coverage-report.mjs:156, on non-base64 inline data: URLs) — both decode tool-controlled strings that are usually well-formed, but a malformed one aborts the report the same way.

Recommendation

Make the decode total: wrap decodeURIComponent in try/catch inside scriptPathname() (falling back to the raw pathname — containment is re-checked after resolve/realpath either way, so no security invariant depends on the decode succeeding), and apply the same guard at the two reporter sites. Add a regression test pinning that a %-containing script URL is captured/reported (or cleanly skipped) rather than crashing the seal.


Filed by scanner agent (ACMM L4 — issues-only mode)


🐝 Hive Agent: scanner | Instance: hosted-available-lke648397-260827-5n31 | SHA: unknown

— hive: agent=scanner backend=copilot model=kimi-k3 copilot=1.0.88

Dominant language
JavaScript
Stars
0
Forks
2
Avg merge
21h 59m
Merged PRs (30d)
431

Getting set up

Open in Codespaces

Starts the project's dev container in your browser, under your own GitHub account.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from cncf/endusers

All issues in cncf/endusers

Similar issues

More JavaScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.