Skip to content

Security Vulnerability #1477

Description

@EgidioRomano

Hi!

On December 23, 2020 I've tried to reach out to you in order to report details about a security vulnerability in Docsify.js, but I still haven't received any response to my email. Is there an appropriate channel where I should report the security issue?

Activity

  1. anikethsaha commented on Jan 13, 2021

    @anikethsaha
    Member

    Can you mail Snyk first regarding the vulnerability. And we will take action once there is a confirmation from them.
    Also, feel free to DM us in discord if it helps.
    Thanks.

  2. added a commit that references this issue on Feb 5, 2021
    e6c6abb
  3. added a commit that references this issue on Feb 5, 2021
    14ce7f3
  4. added a commit that references this issue on Feb 14, 2021
    8c1ae12
  5. added a commit that references this issue on Feb 18, 2021
    ff2a66f
  6. EgidioRomano commented on Feb 22, 2021

    @EgidioRomano
    Author

    Hi @anikethsaha,

    I can still reproduce the vulnerability with docsify version 4.12.0. By using more than two forward slashes (i.e. ///) is still possible to load an external URL and its HTML content is not correctly sanitized, both in the sidebar and main page:

    Schermata da 2021-02-22 15-13-20

  7. sy-records commented on Feb 23, 2021

    @sy-records
    Member

    @EgidioRomano Can you use this for testing?

    <link rel="stylesheet" href="//cdn.jsdelivr.net/gh/sy-records/docsify-nightly/lib/themes/vue.css" />
    
    <script src="//cdn.jsdelivr.net/gh/sy-records/docsify-nightly/lib/docsify.min.js"></script>

    or use https://docsify-preview.now.sh/ testing

  8. EgidioRomano commented on Feb 23, 2021

    @EgidioRomano
    Author

    Hi @sy-records,

    My Proof of Concept doesn't work on https://docsify-preview.now.sh.
    Is it running a different version than the one at https://docsify.js.org ?

  9. sy-records commented on Feb 24, 2021

    @sy-records
    Member

    Yes, docsify-preview.now.sh is the develop branch preview, docsify.js.org is the master branch.
    You can use my nightly version https://github.com/sy-records/docsify-nightly

  10. snoopysecurity commented on Feb 25, 2021

    @snoopysecurity

    If the fix is with the dev branch, is it possible to push it to master and publish a new release @sy-records?

  11. sy-records commented on Feb 26, 2021

    @sy-records
    Member

    If the fix is with the dev branch, is it possible to push it to master and publish a new release @sy-records?

    cc @docsifyjs/reviewers

  12. Koooooo-7 commented on Feb 26, 2021

    @Koooooo-7
    Member

    @sy-records I think we can release a patch on this recently, maybe next week.
    I will review some new PRs at this weekend.

  13. jhildenbiddle commented on Feb 26, 2021

    @jhildenbiddle
    Member

    @sy-records Yes, we should push a patch release to address the security issue ASAP.

  14. snoopysecurity commented on Mar 4, 2021

    @snoopysecurity

    Any update on this? thanks

  15. sy-records commented on Mar 5, 2021

    @sy-records
    Member
  16. volosied commented on Jun 15, 2023

    @volosied

    This vulnerability seems to still exist. I'm able to reproduced it against 4.13.

    I cannot produce it against https://docsify-preview.vercel.app/#/ (which just gives a 404 - Not found instead).

    So I think it's fixed in development? Can a new release be done? Thanks.

  17. sy-records commented on Jun 16, 2023

    @sy-records
    Member

    @volosied I think it should have been released, can you send me the reproduction script?

  18. volosied commented on Jun 16, 2023

    @volosied

    @sy-records

    This issue was discovered by another individual. He provided the following page to test with. See here:

  19. sy-records commented on Jun 16, 2023

    @sy-records
    Member

    yeah, I know, fixed via #2093

  20. henningn commented on Jun 23, 2023

    @henningn

    @sy-records thanks for your work! When can we expect a new release?

  21. Koooooo-7 commented on Jun 23, 2023

    @Koooooo-7
    Member

    Hi @henningn , I think we gonna have a patch of this asap.

    Hi @sy-records , could u plz raise the new release based on the last release commit as a hotfix instead of current dev branch? since we have marked changes need more clarify... if u are not free for this recently, u could ask me to do so as well.

  22. sy-records commented on Jun 24, 2023

    @sy-records
    Member

    see #2101

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions