Where: oxyroute/docs_ui.py:51 (Scalar: https://cdn.jsdelivr.net/npm/@scalar/api-reference, no version pin), :65,:70 (Swagger UI: pinned to major version @5 only, no integrity/crossorigin attribute on either).
If the CDN or the npm package is compromised, the docs page executes arbitrary JS in the API's origin — worse for Scalar since it has no version pin at all, so a malicious/broken publish is served immediately with no way to pin a known-good version.
Fix direction: pin exact versions for both, add Subresource Integrity (integrity/crossorigin="anonymous") hashes for the pinned versions, and consider allowing self-hosted assets as an alternative to CDN loading.
Where:
oxyroute/docs_ui.py:51(Scalar:https://cdn.jsdelivr.net/npm/@scalar/api-reference, no version pin),:65,:70(Swagger UI: pinned to major version@5only, nointegrity/crossoriginattribute on either).If the CDN or the npm package is compromised, the docs page executes arbitrary JS in the API's origin — worse for Scalar since it has no version pin at all, so a malicious/broken publish is served immediately with no way to pin a known-good version.
Fix direction: pin exact versions for both, add Subresource Integrity (
integrity/crossorigin="anonymous") hashes for the pinned versions, and consider allowing self-hosted assets as an alternative to CDN loading.