mirror of
https://github.com/usestrix/strix.git
synced 2026-08-22 02:58:39 +02:00
fix(report): prevent code-fence breakout in vulnerability markdown (#817)
* fix(report): prevent code-fence breakout in vulnerability markdown render_vulnerability_md wrapped LLM-authored poc_script_code and code snippet values in a fixed three-backtick fence, so a triple-backtick inside the value closed the fence early and the rest rendered as live markdown (headings, tracking-beacon images) in the shareable report deliverable. Open each such block with a fence one backtick longer than the longest backtick run in the payload (CommonMark: a block closes only on a fence at least as long as the opener), so the content always renders verbatim. The adjacent ```diff block is already safe (its lines are '- '/'+ ' prefixed and so can never be a bare-backtick closing fence) and is left unchanged. Fixes #815 * fix(report): indent multiline snippets --------- Co-authored-by: thejesh23 <thejesh23@users.noreply.github.com> Co-authored-by: Alex Schapiro <bearsyankees@gmail.com>
This commit is contained in:
co-authored by
thejesh23
Alex Schapiro
parent
f9890a672d
commit
f967e6017b
@@ -113,6 +113,28 @@ def test_render_vulnerability_md_includes_dependency_fields() -> None:
|
||||
assert "## Assumptions" in md
|
||||
|
||||
|
||||
def test_render_vulnerability_md_poc_code_cannot_break_out_of_fence() -> None:
|
||||
# LLM/target-authored PoC content containing its own ``` must not close the
|
||||
# fence early and turn the injected markdown into live headings/images.
|
||||
injected = "curl x\n```\n\n## Injected Heading\n"
|
||||
md = render_vulnerability_md(_sample_report(poc_script_code=injected))
|
||||
lines = md.split("\n")
|
||||
fence = next(ln for ln in lines[lines.index("## Proof of Concept") + 1 :] if ln.strip())
|
||||
assert set(fence) == {"`"}
|
||||
assert len(fence) >= 4 # wider than the payload's 3-backtick run
|
||||
assert injected in md # the payload survives verbatim, inside the fence
|
||||
|
||||
|
||||
def test_render_vulnerability_md_snippet_cannot_break_out_of_fence() -> None:
|
||||
snippet = "row = q()\n```\n## Injected"
|
||||
md = render_vulnerability_md(
|
||||
_sample_report(code_locations=[{"file": "app.py", "snippet": snippet}]),
|
||||
)
|
||||
assert (
|
||||
" ````\n row = q()\n ```\n ## Injected\n ````"
|
||||
) in md # indented fence widened past the payload's ``` run
|
||||
|
||||
|
||||
def test_write_vulnerabilities_creates_markdown_csv_and_json(tmp_path: Path) -> None:
|
||||
reports = [
|
||||
_sample_report(id="vuln-0001", severity="medium", timestamp="2026-07-02 11:00:00 UTC"),
|
||||
|
||||
Reference in New Issue
Block a user