From fcf5dc4da08fa0dc566f9663960f4fa592a024f2 Mon Sep 17 00:00:00 2001 From: Carla Date: Tue, 8 Sep 2026 14:21:05 +0200 Subject: [PATCH] fix: Sanitize vulnerability --- packages/devkit/src/util.js | 24 +++++++++++++++++++++--- 1 file changed, 21 insertions(+), 3 deletions(-) diff --git a/packages/devkit/src/util.js b/packages/devkit/src/util.js index 1710bbff7..eefffdc0f 100644 --- a/packages/devkit/src/util.js +++ b/packages/devkit/src/util.js @@ -450,16 +450,34 @@ export default class Util { * @static */ static htmlSanitize(html) { - const annotationRegex = /\/; + const annotationRegex = /(]*>)([\s\S]*?)(<\/annotation>)/i; // Get all the annotation content including the tags. const annotation = html.match(annotationRegex); + // Sanitize html code without removing our supported MathML tags and attributes. html = DOMPurify.sanitize(html, { ADD_TAGS: ["semantics", "annotation", "mstack", "msline", "msrow", "none"], ADD_ATTR: ["linebreak", "charalign", "stackalign"], }); - // Readd old annotation content. - return html.replace(annotationRegex, annotation); + + if (annotation) { + const startTag = annotation[1]; + const content = annotation[2]; + const endTag = annotation[3]; + + // Encode strictly <, >, and & to their HTML entities to force the browser to render any HTML as text. + const safeContent = content + .replace(/&/g, "&") + .replace(//g, ">"); + + const safeAnnotation = startTag + safeContent + endTag; + + // Re-insert the safely encoded annotation content. + html = html.replace(annotationRegex, safeAnnotation); + } + + return html; } /**