From 0e672d4359b67bc6807c913e8815009d6a7e986e Mon Sep 17 00:00:00 2001 From: "google-labs-jules[bot]" <161369871+google-labs-jules[bot]@users.noreply.github.com> Date: Sat, 3 Oct 2026 10:41:26 +0000 Subject: [PATCH] =?UTF-8?q?=F0=9F=9B=A1=EF=B8=8F=20Sentinel:=20Fix=20XSS?= =?UTF-8?q?=20vulnerability=20in=20email=20preview?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Replaced dynamically rendered dangerouslySetInnerHTML block with a sandboxed iframe using srcDoc to prevent potential XSS vulnerabilities in the email preview panel. Co-authored-by: brycejohnson1417 <257422776+brycejohnson1417@users.noreply.github.com> --- .jules/sentinel.md | 4 ++++ components/accounts/ppp-savings-panel.tsx | 7 ++++++- 2 files changed, 10 insertions(+), 1 deletion(-) create mode 100644 .jules/sentinel.md diff --git a/.jules/sentinel.md b/.jules/sentinel.md new file mode 100644 index 0000000..8282944 --- /dev/null +++ b/.jules/sentinel.md @@ -0,0 +1,4 @@ +## 2024-05-24 - XSS Risk in Email Previews +**Vulnerability:** Using dangerouslySetInnerHTML to render email previews. +**Learning:** Even with DOMPurify, rendering untrusted HTML with dangerouslySetInnerHTML poses an XSS risk. +**Prevention:** Use a sandboxed iframe with srcDoc instead to create an isolated browsing context. diff --git a/components/accounts/ppp-savings-panel.tsx b/components/accounts/ppp-savings-panel.tsx index e6d961b..d9b6771 100644 --- a/components/accounts/ppp-savings-panel.tsx +++ b/components/accounts/ppp-savings-panel.tsx @@ -233,7 +233,12 @@ export function PppSavingsPanel({ orgSlug, accountId }: PppSavingsPanelProps) {