Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Scanner hardening strategy: move SVG/MDX active-content scanning off per-bypass regex patching

Open
#1,194 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
35/100
Issue type
Refactor
Clarity
Mostly clear
Activity status
Active
Tech stack
javascript
Domain
security

Research direction

Start by reading scripts/lib/svg-active-content.mjs and scripts/lib/architecture-content.mjs, then run tests/svg-active-content.test.mjs to understand the historical bypass fixtures. The issue asks for a discussion or ADR to choose parser-based scanning, sanitization, or both; implementation scope depends on that decision. Done means the chosen approach passes the full fixture corpus and residual risks are documented alongside the rules from #1096.

Written by the indexing model from the issue text.

Description

enhancement security

Problem: the bypass class keeps recurring; per-bypass patching is losing

The import-pipeline content scanner (scripts/lib/svg-active-content.mjs, scripts/lib/architecture-content.mjs) accumulated roughly ten distinct bypass classes in one week of sec-check findings, each fixed by another regex:

  • #1005 internal DTD entities; #1023 DOCTYPE external identifiers containing '['
  • #1038 / #1121 MDX hidden by multi-line or block-crossing code spans
  • #1043 CDATA-hidden </style>; #1089 CSS escapes; #1091 CSS comments
  • #1067 backslash authority prefixes; #1175 image-set() bare strings
  • #1167 data: markup media types; #1180 protocol-relative image hosts

svg-active-content.mjs currently performs its analysis through 13 regex operations over text that is actually XML + CSS. Each finding above is the same root cause: regexes approximate grammars that have escaping, comments, and tokenizer states the regex cannot see. The historical rate (~10/week) predicts the next bypass; the per-bypass loop produces unbounded future work and a permanently uncertain gate.

Proposed direction (pick via discussion)

  1. Parse, do not pattern-match. Run SVG through a real XML parser (e.g. @rgrove/parse-xml or sax) and walk the element/attribute tree; tokenize embedded CSS with a real CSS tokenizer before looking for remote targets. Grammar-level analysis eliminates the escaping/comment/CDATA class wholesale.
  2. Sanitize instead of scan-and-reject for the mirror path: project the SVG onto an element/attribute allowlist (DOMPurify-style, or rebuild from the parsed tree), so unknown constructs are dropped rather than needing to be anticipated.
  3. Defense in depth at serve time: the CSP currently ships only as a <meta http-equiv> tag (docusaurus.config.js:148), which cannot cover everything response headers can on GitHub Pages — document this residual risk and the compensating controls in the content-security doc requested by #1096.

Keep the existing regression test corpus (tests/svg-active-content.test.mjs) as the acceptance suite: every past bypass becomes a fixture the parser-based gate must still reject.

Completion criteria

  • A decision (ADR or issue consensus) on parser-based scanning vs sanitization vs both.
  • The chosen implementation passes the full historical-bypass fixture corpus.
  • Residual risks documented alongside the submitter-facing rules from #1096.

Refs #1096 (documentation counterpart).

Dominant language
JavaScript
Stars
0
Forks
2
Avg merge
21h 59m
Merged PRs (30d)
431

Getting set up

Open in Codespaces

Starts the project's dev container in your browser, under your own GitHub account.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from cncf/endusers

All issues in cncf/endusers

Similar issues

More JavaScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.