Repository navigation
Fix #24: Sanitize Node Metadata Inputs #29
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -69,20 +69,24 @@ public function generateMermaidString(): string | |
|
|
||
| foreach ($controllers as $name => $data) { | ||
| $ctrlId = "C_" . md5($name); | ||
| $mermaidLines[] = " subgraph {$ctrlId} [\"$name\"]"; | ||
| $safeName = htmlspecialchars($name, ENT_QUOTES, 'UTF-8'); | ||
| $mermaidLines[] = " subgraph {$ctrlId} [\"$safeName\"]"; | ||
|
|
||
| foreach ($data['routes'] as $r) { | ||
| $routeId = "R_" . md5($r['uri']); | ||
| $methodId = "M_" . md5($r['uri'] . $r['action']); | ||
|
|
||
| // Route Node with Middleware | ||
| $label = "/{$r['uri']}"; | ||
| $safeUri = htmlspecialchars($r['uri'], ENT_QUOTES, 'UTF-8'); | ||
| $label = "/{$safeUri}"; | ||
| if ($r['middleware']) { | ||
| $label .= " <br/><small>🔐 {$r['middleware']}</small>"; | ||
| $safeMiddleware = htmlspecialchars($r['middleware'], ENT_QUOTES, 'UTF-8'); | ||
| $label .= " <br/><small>🔐 {$safeMiddleware}</small>"; | ||
| } | ||
|
|
||
| $safeAction = htmlspecialchars($r['action'], ENT_QUOTES, 'UTF-8'); | ||
| $mermaidLines[] = " {$routeId}([\"$label\"]):::route"; | ||
| $mermaidLines[] = " {$methodId}(\"{$r['action']}\"):::method"; | ||
| $mermaidLines[] = " {$methodId}(\"{$safeAction}\"):::method"; | ||
|
Comment on lines
+72
to
+89
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🔴 Critical | 🏗️ Heavy lift 🧩 Analysis chain🏁 Script executed: #!/usr/bin/env bash
set -euo pipefail
version="${MERMAID_VERSION:-10.9.6}"
base="https://raw.githubusercontent.com/mermaid-js/mermaid/v${version}/packages/mermaid/src"
integration="$(curl -fsSL "$base/mermaid.ts")"
api="$(curl -fsSL "$base/mermaidAPI.ts")"
grep -Fq 'txt = element.innerHTML' <<<"$integration"
grep -Fq 'utils.entityDecode(txt)' <<<"$integration"
grep -Fq 'else if (!isLooseSecurityLevel)' <<<"$api"
echo "Verified Mermaid ${version} parsing and loose-mode sanitization behavior."Repository: diusazzad/LaraNexus Length of output: 227 🏁 Script executed: #!/usr/bin/env bash
set -euo pipefail
echo "== Locate relevant files =="
fd -a 'RouteMapCollector.php|*.blade.php|composer.lock|package.json|pnpm-lock.yaml|yarn.lock|package-lock.json' . \
| sed 's#^\./##' | head -200
echo
echo "== RouteMapCollector excerpt =="
file="$(fd 'RouteMapCollector.php' . | head -1)"
if [ "${file:-}" != "" ]; then
wc -l "$file"
sed -n '1,160p' "$file" | nl -ba
fi
echo
echo "== Mermaid config/usages through raw blade or securityLevel =="
rg -n --hidden --glob '!vendor/**' --glob '!node_modules/**' "securityLevel|DOMPurify|\.mermaid|innerHTML|RouteMapCollector|mermaid" . | head -300
echo
echo "== Composer/package Mermaid references =="
rg -n --hidden --glob '!vendor/**' --glob '!node_modules/**' "mermaid|viz" composer.json composer.lock package.json pnpm-lock.yaml yarn.lock package-lock.json 2>/dev/null || trueRepository: diusazzad/LaraNexus Length of output: 590 🏁 Script executed: #!/usr/bin/env bash
set -euo pipefail
echo "== Locate relevant files =="
files=()
for p in packages/diusazzad/laranexus/src/Support/RouteMapCollector.php; do
[ -f "$p" ] && files+=("$p")
done
fd 'RouteMapCollector.php$' . packages || true
fd '\.blade\.php$' . packages || true
for f in composer.lock package.json pnpm-lock.yaml yarn.lock package-lock.json; do
[ -f "$f" ] && files+=("$f")
done
printf '%s\n' "${files[@]}"
file="$(fd 'RouteMapCollector.php$' . packages | head -1 || true)"
if [ -n "${file:-}" ]; then
echo
echo "== RouteMapCollector excerpt =="
wc -l "$file"
sed -n '1,170p' "$file" | nl -ba
fi
echo
echo "== Mermaid config/usages through raw blade or securityLevel =="
rg -n --hidden --glob '!vendor/**' --glob '!node_modules/**' "securityLevel|DOMPurify|\.mermaid|innerHTML|RouteMapCollector|mermaid" . packages || true
echo
echo "== Composer/package Mermaid references =="
for f in composer.json composer.lock package.json pnpm-lock.yaml yarn.lock package-lock.json; do
[ -f "$f" ] && { echo "--- $f"; rg -n 'mermaid|viz' "$f" || true; }
doneRepository: diusazzad/LaraNexus Length of output: 864 🏁 Script executed: #!/usr/bin/env bash
set -euo pipefail
echo "== RouteMapCollector excerpt =="
sed -n '1,170p' packages/diusazzad/laranexus/src/Support/RouteMapCollector.php
echo
echo "== Dashboard and relevant Blade excerpts =="
sed -n '1,240p' packages/diusazzad/laranexus/resources/views/dashboard.blade.php
rg -n --hidden --glob '!vendor/**' --glob '!node_modules/**' "RouteMapCollector|mermaid|securityLevel|innerHTML|`@raw`|dangerouslySetInnerHTML" packages/diusazzad/laranexus resources . | head -200
echo
echo "== Mermaid package references =="
for f in composer.json composer.lock package.json pnpm-lock.yaml yarn.lock package-lock.json; do
[ -f "$f" ] && { echo "--- $f"; rg -n 'mermaid|viz' "$f" || true; }
doneRepository: diusazzad/LaraNexus Length of output: 25764 🌐 Web query:
💡 Result: In Mermaid, the interaction between Citations:
🌐 Web query:
💡 Result: The vulnerability identified as GHSA-7rqq-prvp-x9jh (also tracked as CVE-2025-54881) is a Cross-Site Scripting (XSS) flaw in the Mermaid.js library [1][2][3]. The vulnerability stems from improper sanitization of user-supplied input in sequence diagram labels [1][2]. Specifically, the library's Citations:
🌐 Web query:
💡 Result: In the context of the Mermaid.js library (specifically versions like v10.9.6), the code snippet involving Citations:
Don’t rely on The dashboard renders Also applies to: 103-111 🧰 Tools🪛 ast-grep (0.45.0)[error] 75-75: Do not use a weak hash algorithm (weak-hash-algorithm) [error] 76-76: Do not use a weak hash algorithm (weak-hash-algorithm) 🤖 Prompt for AI AgentsSource: MCP tools |
||
| $mermaidLines[] = " {$routeId} --> {$methodId}"; | ||
|
|
||
| // Discovery Logic (Same as before but nested) | ||
|
|
@@ -96,13 +100,15 @@ public function generateMermaidString(): string | |
| preg_match_all('/use App\\\Models\\\([a-zA-Z]+);/', $content, $modelMatches); | ||
| foreach (array_unique($modelMatches[1]) as $modelName) { | ||
| $modelId = "Mod_" . md5($modelName); | ||
| $mermaidLines[] = " {$methodId} -- uses --> {$modelId}[(\"DB: $modelName\")]:::model"; | ||
| $safeModel = htmlspecialchars($modelName, ENT_QUOTES, 'UTF-8'); | ||
| $mermaidLines[] = " {$methodId} -- uses --> {$modelId}[(\"DB: $safeModel\")]:::model"; | ||
| } | ||
|
|
||
| preg_match_all('/view\([\'"]([a-zA-Z0-9._-]+)[\'"]\)/', $content, $viewMatches); | ||
| foreach (array_unique($viewMatches[1]) as $viewName) { | ||
| $viewId = "V_" . md5($viewName); | ||
| $mermaidLines[] = " {$methodId} -- renders --> {$viewId}[[\"View: $viewName\"]]:::view"; | ||
| $safeView = htmlspecialchars($viewName, ENT_QUOTES, 'UTF-8'); | ||
| $mermaidLines[] = " {$methodId} -- renders --> {$viewId}[[\"View: $safeView\"]]:::view"; | ||
| } | ||
| } | ||
| } | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win
🧩 Analysis chain
🏁 Script executed:
Repository: diusazzad/LaraNexus
Length of output: 5340
Preserve
ENT_SUBSTITUTEwhen escaping Mermaid labels.The default flags are not preserved when only
ENT_QUOTESis passed, so invalid UTF-8 in names, routes, middleware, actions, models, or views turns into an empty string and can silently erase labels. AddENT_SUBSTITUTEto thesehtmlspecialchars()calls.Suggested change
📝 Committable suggestion
🤖 Prompt for AI Agents
Source: MCP tools