diff --git a/.jules/sentinel.md b/.jules/sentinel.md new file mode 100644 index 0000000..07df5fb --- /dev/null +++ b/.jules/sentinel.md @@ -0,0 +1,4 @@ +## 2024-07-06 - XSS Vulnerability in Email Previews via dangerouslySetInnerHTML +**Vulnerability:** The `PppSavingsPanel` component uses `dangerouslySetInnerHTML` to render email previews. Even though `DOMPurify.sanitize` is used, displaying user-controlled or external HTML directly into the DOM can still pose subtle XSS risks or styling leakage, especially if `DOMPurify` configuration is not sufficiently restrictive. +**Learning:** Using `dangerouslySetInnerHTML` combined with a sanitizer is not always sufficient for rendering complex or untrusted HTML like email templates. It is safer to isolate the rendering context entirely to prevent both XSS and CSS injection that could affect the main application layout. +**Prevention:** Prioritize using a sandboxed `