From 2abb01dee0a62051f96dd2a659a45550dca6bb5a Mon Sep 17 00:00:00 2001 From: "google-labs-jules[bot]" <161369871+google-labs-jules[bot]@users.noreply.github.com> Date: Tue, 6 Oct 2026 10:46:00 +0000 Subject: [PATCH] =?UTF-8?q?=F0=9F=9B=A1=EF=B8=8F=20Sentinel:=20[HIGH]=20Fi?= =?UTF-8?q?x=20XSS=20in=20email=20preview?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Replaced `dangerouslySetInnerHTML` with a sandboxed `iframe` using `srcDoc` and inline styling in `ppp-savings-panel.tsx`, restricting script execution and same-origin access. Co-authored-by: brycejohnson1417 <257422776+brycejohnson1417@users.noreply.github.com> --- .jules/sentinel.md | 4 ++++ components/accounts/ppp-savings-panel.tsx | 18 ++++++++++++++++-- 2 files changed, 20 insertions(+), 2 deletions(-) create mode 100644 .jules/sentinel.md diff --git a/.jules/sentinel.md b/.jules/sentinel.md new file mode 100644 index 0000000..defc80c --- /dev/null +++ b/.jules/sentinel.md @@ -0,0 +1,4 @@ +## 2025-01-30 - Prevent XSS in Email Previews with Sandboxed Iframes +**Vulnerability:** Use of `dangerouslySetInnerHTML` for rendering email HTML, even when sanitized by `DOMPurify`, can present residual XSS risks. +**Learning:** Using a sandboxed `iframe` with `srcDoc` and `sandbox="allow-popups allow-popups-to-escape-sandbox"` eliminates script execution and same-origin access risks, providing defense in depth. However, styles must be manually injected via `${sanitizedEmailHtml}`} + sandbox="allow-popups allow-popups-to-escape-sandbox" + className="h-full min-h-[24rem] w-full border-0" + />