Repository navigation
fix(security): reject remote image destinations in imported MDX pages - #1255
Merged
Merged
Conversation
findActiveContent() answered only the first of the two questions scripts/lib/uri-safety.mjs states both content gates must answer: does the value run script, and does it make a visitor's browser contact another host. The SVG gate answers both (findActiveContent plus findRemoteReferences); the MDX gate never called remoteTarget(), so a remote <img> in a page imported verbatim from cncf/architecture published as a third-party beacon. Checked, scoped to destinations a browser fetches with no user action: image nodes, imageReference nodes resolved through their definition, and the logo attribute of CNCFProjectCard, which reaches an <img src> through useBaseUrl(). Links, link definitions and the card's remote href are deliberately untouched: rewriteImages() demotes a remote image to a remote link, and imported pages carry legitimate remote link definitions. Closes #1254 Signed-off-by: sec-check <sec-check@hive.kubestellar.io>
Contributor
Author
|
Important Held for human review by the hive's ACMM level gate. This PR was opened by the "sec-check" agent while Hive policy required a human checkpoint for that agent. Non-outreach agents are held at ACMM L3–L5; the Hive will keep the |
This was referenced Oct 9, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Security Fix
scripts/lib/uri-safety.mjsstates the invariant both content gates are builton: each must decide "does it run script, and does it make a visitor's browser
contact another host", and a question one gate asks and the other does not is a
bypass of the more permissive one.
The SVG gate asks both —
findActiveContent()andfindRemoteReferences().The MDX gate asked only the first:
findActiveContent()inscripts/lib/mdx-active-content.mjsnever calledremoteTarget(), so a remoteimage destination in a page imported verbatim from
cncf/architecturepassedthe only gate that runs on published pages
(
scripts/validate-architectures.mjs:142) and shipped as a third-party beaconfor every visitor's IP, User-Agent and Referer.
What this changes
findActiveContent()now reports aremote image destination, scoped to thedestinations a browser fetches with no user action:
imagenodes whoseurlis a remote target;imageReferencenodes, resolved through theirdefinition(the definitionnode itself is not flagged —
linkReferenceresolves through the same map);logoattribute ofCNCFProjectCard, the only allowed attribute thatreaches an
<img src>: it is passed throughuseBaseUrl(), which returns anabsolute URL unchanged (
src/components/CNCFProjectCard/index.js:16,20).Deliberately untouched, because flagging them would reject every imported page:
ordinary links, remote link definitions (
docs/architectures/colopl.md:48-52),and the card's
href, which is remote by contract.Verification
node scripts/validate-architectures.mjs→Validated 8 architecture recordson the current
docs/architectures/tree, unchanged.npm run test:unit:coverage:checkexits 0;scripts/lib/mdx-active-content.mjsis at 100.00% lines / 100.00% regions.
npx prettier --checkclean on both changed files.Files claimed by this PR:
scripts/lib/mdx-active-content.mjs,tests/mdx-active-content.test.mjs. Disjoint from the open hold-gated PRs(#1249
scripts/lib/uri-safety.mjs+tests/svg-active-content.test.mjs,#1250
package.json+tests/coverage-gate-thresholds.test.mjs,#1252
tests/e2e-coverage-source-boundary-segments.test.mjs). This PR importsremoteTarget/describeTargetfromuri-safety.mjsbut does not edit it, soit composes with #1249 rather than conflicting with it.
Closes #1254
Filed by sec-check agent (ACMM L4/L5 — hold-gated mode). Hold-gated: human review required.
— hive: agent=sec-check backend=copilot model=claude-opus-5 copilot=1.0.88