Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Repository-influenced model output is rendered as active slide HTML

Aperta
#606 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
3/5
Tempo stimato
1-2 giorni
Idoneità per principianti
35/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Ferma
Stack tecnologico
typescript
Ambito
frontend, security

Direzione di ricerca

Start in src/app/[owner]/[repo]/slides/page.tsx, where repository wiki content is prompted into slide HTML, extracted, and rendered through dangerouslySetInnerHTML. Review the extraction fallback and rendering path, then verify that repository-controlled model output cannot execute scripts or event handlers when the Slides view is opened; the issue notes that a fix is already in a linked PR.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Affected versions: confirmed on main at commit d92819a9 (the project publishes no tagged release).

Summary

The Slides view (src/app/[owner]/[repo]/slides/page.tsx) places repository-derived wiki content into a prompt asking the model to generate a single HTML slide, extracts HTML from the response with a few regexes, and renders it with dangerouslySetInnerHTML without sanitizing it.

Details

content: `Create a single HTML slide ...
Use the following wiki content as reference:
${wikiContent}
...
I need ONLY the HTML for this slide.`
const codeBlockMatch = slideContent.match(/```(?:html)?\s*([\s\S]*?)\s*```/);
...
slideHtml = slideContent;   // fallback: raw model output, unsanitized
<div className="w-full h-full" dangerouslySetInnerHTML={{ __html: slides[currentSlideIndex]?.html || '' }} />

If the model's own output already contains a <style> tag, the page's default-styling wrapper is skipped entirely and the raw output is used as-is.

POC

(available upon request)

Impact

A repository whose content (README, code comments, etc.) can induce the model to emit an onerror/onclick handler or a <script> tag causes that script to execute in the DeepWiki origin when a victim opens that repository's Slides view.

Suggested fix: sanitize the extracted HTML with a strict sanitizer before rendering, or render it in a sandboxed iframe. A fix is included in the linked PR.

Fix: #599

Lingua principale
Python
Stelle
18.1k
Fork
2k
Metriche di merge delle PR
Nessuna PR unita negli ultimi 30g

Preparare l'ambiente

Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di AsyncFuncAI/deepwiki-open

Tutte le issue di AsyncFuncAI/deepwiki-open

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.