Repository navigation
fix(security): resolve reference-style images before the remote-image demotion in cleanMarkdown - #1229
Closed
hivecommons-hive[bot] wants to merge 1 commit into
Closed
fix(security): resolve reference-style images before the remote-image demotion in cleanMarkdown#1229hivecommons-hive[bot] wants to merge 1 commit into
hivecommons-hive[bot] wants to merge 1 commit into
Conversation
… demotion
cleanMarkdown() demotes a remote image to a plain link so a published
architecture page never hot-links a third-party host, but its pattern
matched only the inline form ``. CommonMark's three
reference forms -- full `![alt][label]`, collapsed `![alt][]` and
shortcut `![alt]` -- keep their destination in a link-reference
definition, so none of them were inspected, demoted or rewritten and the
compiled page rendered the submitted <img> verbatim. Every visitor's
browser then handed that host their IP, User-Agent and Referer.
findActiveContent() reports script-capable schemes and disallowed
elements, not remote resource references, so nothing downstream caught
it either. Both producers share this transform, so the daily
cncf/architecture import and the submission issue form were both
affected; escapeMdx() neutralises < and { but leaves ! and [ alone.
Resolve each reference form against the document's definitions before
the existing image rules run, so every image form reaches the same
demotion and the same local-path rewrite: a cncf/artwork destination now
also reaches its mirrored path and a relative one its
/img/architectures/<id>/ scope instead of rendering broken. A
destination carrying whitespace or parentheses cannot be expressed in
the [^)]+ destinations those rules match, so it fails closed by dropping
the ! and rendering as a link reference, which fetches nothing. The
definition line is left in place: it renders as nothing and may still be
the target of a text link on the same page.
Closes #1228
Signed-off-by: sec-check <sec-check@hive.kubestellar.io>
Contributor
Author
|
Important Held for human review by the hive's ACMM level gate. This PR was opened by the "sec-check" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the Hive will keep the |
Member
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Security Fix
cleanMarkdown()inscripts/lib/architecture-content.mjsdemotes a remoteimage to a plain link so a published architecture page never hot-links a
third-party host. Its pattern matched only the inline form
.CommonMark's three reference forms — full
![alt][label], collapsed![alt][]and shortcut![alt]— keep their destination in a link-referencedefinition elsewhere in the document, so none of them were inspected, demoted
or rewritten and the compiled page rendered the submitted
<img src="https://third-party.example/...">verbatim. Every visitor's browserfetched it on page load, handing that host their IP,
User-AgentandReferer.findActiveContent()reports script-capable schemes and disallowed elements,not remote resource references, so
scripts/validate-architectures.mjsdid notcatch it either. Both producers share this transform, so the unattended daily
cncf/architectureimport and the community submission issue form were bothaffected —
escapeMdx()neutralises<and{but leaves!,[and]alone.
What this changes
inlineImageReferences()resolves each reference form against the document'slink-reference definitions before the existing image rules run, so every image
form reaches the same remote-demotion and the same local-path rewrite:
and for every spelling the inline rule already covers (absolute,
protocol-relative, uppercase scheme, angle-bracketed);
cncf/artworkdestination now reaches its mirrored/img/cncf-projects/...path, and a relative one its
/img/architectures/<id>/...scope, instead ofrendering broken;
internal whitespace collapsed);
[^\)]+destinations the downstream rules match, so it fails closed: the!is dropped and the construct renders as a link reference, which fetches
nothing.
The definition line is left in place — a definition renders as nothing, and it
may still be the target of a text link on the same page.
Verification
node --testovertests/architecture-content-clean-markdown.test.mjs,architecture-content-mirror,import-architecture-issue,import-architecture-issue-project-href,import-architectures,import-architectures-fallbacks,validate-architecturesandarchitecture-catalog-contract: 130 pass, 0 fail. Eight new tests cover thethree reference forms, the destination spellings, label normalisation, the
artwork and relative rewrites, the fail-closed paren destination, a reference
with no definition, and a text link reference (which must not become an image).
npx prettier --checkclean on both files.End to end, the submission-issue repro from the issue now generates
[tracker](https://evil.example/pixel.png)where it previously generated![tracker][beacon]. No checked-in page changes:docs/architectures/colopl.mdis the only page carrying link-reference definitions and they are all text
links.
Scope
Files:
scripts/lib/architecture-content.mjs(cleanMarkdown,new
inlineImageReferences) andtests/architecture-content-clean-markdown.test.mjs. Disjoint from the opensecurity PRs #1206 and #1213 (
scripts/lib/svg-active-content.mjs,tests/svg-active-content.test.mjs) and #1219(
scripts/lib/mdx-active-content.mjs,tests/mdx-active-content.test.mjs).Closes #1228
Hold-gated: human review required.
— hive: agent=sec-check backend=copilot model=claude-opus-5 copilot=1.0.88