Repository navigation
fix(security): honour CSS escapes when pairing quotes in the SVG scanner - #1206
Closed
hivecommons-hive[bot] wants to merge 1 commit into
Closed
hivecommons-hive[bot] wants to merge 1 commit into
hivecommons-hive[bot] wants to merge 1 commit into
Conversation
stripCssComments() and the image-set() argument scan in scripts/lib/svg-active-content.mjs paired CSS quote characters without honouring escape sequences, so a backslash-escaped quote desynchronised both scans and hid a remote resource reference from findRemoteReferences(). " is an escaped quote character and does not open a string, but stripCssComments() read it as one and copied to the next quote in the fragment verbatim, leaving any CSS comment in between unstripped. A comment between a later url( and its quoted argument then survived, and CSS_URL_PATTERN matches neither the commented url( nor the text after it. The same blindness let an unterminated string run past the newline that ends it as a bad-string, blinding the strip for the rest of the fragment. CSS_STRING split "a\"" into two strings rather than one, shifting every later quote by one and leaving a bare-string image-set() target inside what the scan then read as unquoted filler. Both now go through one endOfCssString() helper that skips an escaped code point and ends a string at a newline, matching the tokenizer. Closes #1205 Signed-off-by: sec-check <sec-check@hive.kubestellar.io>
Contributor
Author
|
Important Held for human review by the hive's ACMM level gate. This PR was opened by the "sec-check" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the Hive will keep the |
This was referenced Oct 8, 2026
Member
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Security Fix
scripts/lib/svg-active-content.mjspaired CSS quote characters without honouring escape sequences, in two places. Both desynchronised the scan and hid a remote resource reference fromfindRemoteReferences()— the gatemirrorArtworkUrls(),mirrorLandscapeLogo()andscripts/validate-architecture-assets.mjsrely on to keep a third-party host out of an SVG published fromstatic/at the site origin.stripCssComments()had no backslash handling, sofont-family: \"— an escaped quote character, which does not open a string — was read as a string opener and everything to the next quote in the fragment was copied verbatim, leaving the CSS comments in that span unstripped. A comment between a laterurl(and its quoted argument then survived, andCSS_URL_PATTERNmatches neither the commentedurl(nor the text after it. The same blindness let an unterminated string run past the newline that ends it as a bad-string.CSS_STRINGsplit"a\""into two strings rather than one, shifting every later quote by one and leaving a bare-stringimage-set()target inside what the scan then read as unquoted filler.Both now go through one
endOfCssString()helper that skips an escaped code point and ends a string at a newline, matching the tokenizer.cssStringAt()returns the raw contents on the same rule, replacing theCSS_STRINGregex.Verification
tests/svg-active-content.test.mjs; all three fail onmainand pass here.node --test tests/svg-active-content.test.mjs: 124 pass, 0 fail (121 before).?? ''fallback at line 251; every line added here is exercised.npx prettier --checkclean on both files.css-treeparses the escaped-quote case as two separate rules and theimage-set()case as two strings (a",https://evil.example/shifted.png), confirming the escape changes what this scanner sees and not what the stylesheet means.Files touched:
scripts/lib/svg-active-content.mjs(stripCssComments,imageSetArguments, newendOfCssString/cssStringAt,CSS_STRINGremoved) andtests/svg-active-content.test.mjs. No overlap with #1203.Closes #1205
This is an interim fix on the per-bypass path #1194 describes; it does not substitute for the parser-based direction decided there.
Filed by sec-check agent (ACMM L4/L5 — hold-gated mode). Hold-gated: human review required.
— hive: agent=sec-check backend=copilot model=claude-opus-5 copilot=1.0.88 requested_by=@mrbobbytables