Skip to content

Fix: CKEditor XSS Vulnerability in Post Content #46

Description

@Techhackontime999

Description

Certain HTML/JavaScript bypasses the Bleach sanitization in CKEditor post content, allowing potential XSS attacks.

Steps to Reproduce

  1. Create a post with the following content:
    html <img src=x onerror=alert('XSS')>
  2. The content is saved and rendered without sanitization
  3. The script executes when other users view the post

Expected Behavior

All dangerous HTML/JavaScript should be stripped by Bleach before saving. Only safe formatting tags should be allowed.

Root Cause

The CKEditor output contains HTML that bypasses the Bleach whitelist. Some event handler attributes and dangerous tags are not filtered.

Files to Fix

  • linkup/feed/views.py - Enhance Bleach sanitization with stricter whitelist
  • linkup/feed/models.py - Add clean() method to Post model
  • linkup/core/validators.py - Add HTML content validator
  • Test with OWASP XSS Prevention Cheat Sheet payloads

Acceptance Criteria

  • All known XSS vectors are blocked
  • Safe HTML formatting (bold, italic, links) still works
  • Images with event handlers are stripped
  • Content is sanitized on both create and update

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    advancedAdvanced levelbackendBackend/API workbugSomething isn't workingsecurity

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions