mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-09-30 03:01:21 +02:00
GHSA-cp6q-959q-f8rh: @tiptap/core's mergeAttributes() copies keys out of Object.entries() with plain bracket assignment, so an own __proto__ key from JSON hits the legacy prototype setter rather than writing a property. The result carries an attacker-controlled prototype while Object.keys() and own-property checks show nothing, and ProseMirror's DOMSerializer.renderSpec() enumerates attribute objects with for...in -- so inherited src and onerror land on a rendered <img> and execute. Medium, CVSS 4.0 6.4, fixed in 3.30.4. Not reachable here. The advisory needs an untrusted object arriving at mergeAttributes(), or a custom or dynamic extension that preserves the attribute object. Nothing under frontend/src calls mergeAttributes or defines an extension, and RichTextEditor builds a fixed schema from StarterKit plus six stock extensions whose HTMLAttributes are static literals. Content crosses as an HTML string rather than JSON, so no own __proto__ key reaches an attrs object at all -- the DOM parser only fills attributes the schema declares -- and every read-only render is sanitized. Lockfile only: package.json already declared ^3.11.1, so the patched line was inside the range and only the stale lock held 3.19.0. No overrides entry needed. @tiptap/pm has narrowed its dependency set, so prosemirror-markdown, prosemirror-menu, prosemirror-collab, prosemirror-schema-basic, prosemirror-trailing-node, markdown-it and linkify-it leave the tree -- 16 packages, none imported by this repo. That retires the reachability note carried for linkify-it in 1.2.5. eslint, build with the Safari 16 baseline check, i18n parity and 3514 frontend tests across 256 files all pass. npm audit --omit=dev, which is what CI gates on, reports zero vulnerabilities.
41 lines
1.8 KiB
HTML
41 lines
1.8 KiB
HTML
<!doctype html>
|
|
<html lang="en">
|
|
<head>
|
|
<meta charset="UTF-8" />
|
|
<meta name="viewport" content="width=device-width, initial-scale=1.0, maximum-scale=1.0, user-scalable=no" />
|
|
<!-- L-4: Restrict Referer header to origin-only on cross-origin navigation so
|
|
sensitive tokens in query parameters are not leaked to third-party servers. -->
|
|
<meta name="referrer" content="strict-origin-when-cross-origin" />
|
|
<title>Bambuddy</title>
|
|
|
|
<!-- PWA Meta Tags -->
|
|
<meta name="description" content="Monitor and manage your Bambu Lab 3D printers" />
|
|
<meta name="theme-color" content="#00ae42" />
|
|
<meta name="mobile-web-app-capable" content="yes" />
|
|
<meta name="apple-mobile-web-app-capable" content="yes" />
|
|
<meta name="apple-mobile-web-app-status-bar-style" content="black-translucent" />
|
|
<meta name="apple-mobile-web-app-title" content="Bambuddy" />
|
|
|
|
<!-- Manifest -->
|
|
<link rel="manifest" href="/manifest.json" />
|
|
|
|
<!-- Favicons -->
|
|
<link rel="icon" type="image/png" sizes="32x32" href="/img/favicon-32x32.png" />
|
|
<link rel="icon" type="image/png" sizes="16x16" href="/img/favicon-16x16.png" />
|
|
<link rel="apple-touch-icon" sizes="180x180" href="/img/apple-touch-icon.png" />
|
|
|
|
<!-- Splash screens for iOS -->
|
|
<link rel="apple-touch-startup-image" href="/img/android-chrome-512x512.png" />
|
|
<script type="module" crossorigin src="/assets/index-CH-LgsSx.js"></script>
|
|
<link rel="stylesheet" crossorigin href="/assets/index-DR-aOvsI.css">
|
|
</head>
|
|
<body>
|
|
<div id="root"></div>
|
|
|
|
<!-- Service Worker Registration (skip on SpoolBuddy kiosk).
|
|
Kept as an external file so the CSP `script-src 'self'` covers it
|
|
without needing 'unsafe-inline' or per-build hashes. -->
|
|
<script src="/sw-register.js"></script>
|
|
</body>
|
|
</html>
|