# XSS vulnerability in HTMLSanitizer might be insufficiently handled

**URL:** https://discourse.aurelia.io/t/xss-vulnerability-in-htmlsanitizer-might-be-insufficiently-handled/4219
**Category:** Framework Knowledge
**Created:** [May 16, 2021, 7:57pm UTC](https://discourse.aurelia.io/t/xss-vulnerability-in-htmlsanitizer-might-be-insufficiently-handled/4219 "2021-05-16T19:57:36Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![dabide](https://yyz1.discourse-cdn.com/flex027/user_avatar/discourse.aurelia.io/dabide/32/2078_2.png) [@dabide](https://discourse.aurelia.io/u/dabide)
#### Post date: [May 16, 2021, 7:57pm UTC](https://discourse.aurelia.io/t/xss-vulnerability-in-htmlsanitizer-might-be-insufficiently-handled/4219/1 "2021-05-16T19:57:36Z")

</div>

As stated elsewhere, @MedAziz1 [recently blogged](https://www.gosecure.net/blog/2021/05/12/aurelia-framework-insecure-default-allows-xss/) about the vulnerability in HTMLSanitizer that [he reported back in 2019](https://discourse.aurelia.io/t/vulnerability-disclosure-contact/2390), resulting amongst other in [this article](https://portswigger.net/daily-swig/aurelia-frameworks-default-html-sanitizer-opens-the-door-to-xss-attacks) and a [tweet by the CVE team](https://twitter.com/CVEnew/status/1392959116683923457).

Aziz also expresses these worries: “The 2.0 version of its framework hasn’t been released and its biggest 1.x contributor is now working at Microsoft on [fast](https://www.fast.design/) so it remains to be seen what the future of the Aurelia framework [and its security] is,” he commented.

In the original discussion, @EisenbergEffect concluded this way:

> [@Vulnerability Disclosure Contact](https://discourse.aurelia.io/t/vulnerability-disclosure-contact/2390/6):
>
> The concern that was raised was with Aurelia’s internal HTMLSanitizer. However, per our docs, we indicate that it’s only a dev version and should not be used in production. So, there’s not really a security issue. We’ve updated our docs to add further clarity and guidance on how to replace the sanitizer with a production-grade implementation. We’ve also shipped an update that prints a warning to the console when you use our sanitizer.

I am not convinced that this addresses the concerns sufficiently. Many people will use the `sanitizeHTML` value converter without knowing about the issues, especially if they started using it before the docs were edited in 2019. There’s no guarantee that they will see the warning in the console, either.

My suggestion would be the following:

1. Make `HTMLSanitizer` throw an error in its `sanitize()` function, requiring supplying a “real” implementation to work at all.
2. Deprecate all previous versions of the [aurelia-templating-resources](https://www.npmjs.com/package/aurelia-templating-resources) NPM package, and possibly also [aurelia-bootstrapper](https://www.npmjs.com/package/aurelia-bootstrapper).
3. (Perhaps too radical?) Make `innerhtml.bind` require and use a sanitizer implementation, with an explicit option to override.

---

<div class="post-metadata">

### Author: ![MedAziz1](https://avatars.discourse-cdn.com/v4/letter/m/cc9497/32.png) [@MedAziz1](https://discourse.aurelia.io/u/MedAziz1)
#### Post date: [May 17, 2021, 10:46pm UTC](https://discourse.aurelia.io/t/xss-vulnerability-in-htmlsanitizer-might-be-insufficiently-handled/4219/2 "2021-05-17T22:46:00Z")

</div>

Hello There,

Since there is already a discussion for this, I’d like to add a little something.  
In the last couple of days, I’ve decided to check the pre-release version of Aurelia 2. I found that this issue appears to have found its way there . As can be seen below, the same default sanitizer (written in a slightly different way) is being used on the untrusted markup.

Concerned file:

> <https://github.com/aurelia/aurelia/blob/master/packages/runtime-html/src/resources/value-converters/sanitize.ts>

---

<div class="post-metadata">

### Author: ![dabide](https://yyz1.discourse-cdn.com/flex027/user_avatar/discourse.aurelia.io/dabide/32/2078_2.png) [@dabide](https://discourse.aurelia.io/u/dabide)
#### Post date: [May 19, 2021, 6:46am UTC](https://discourse.aurelia.io/t/xss-vulnerability-in-htmlsanitizer-might-be-insufficiently-handled/4219/3 "2021-05-19T06:46:31Z")

</div>

I created an issue for this:

> <https://github.com/aurelia/aurelia/issues/1165>
>
> \# 💬 RFC
> \## 🔦
> @MedAziz1 yesterday \[pointed out on the Aurelia Discord\](https://…discourse.aurelia.io/t/xss-vulnerability-in-htmlsanitizer-might-be-insufficiently-handled/4219/2?u=dabide) that Aurelia 2 has the same vulnerability in its default HTML sanitizer implementation that Aurelia 1 has: https://github.com/aurelia/aurelia/blob/master/packages/runtime-html/src/resources/value-converters/sanitize.ts
> 
> \`ISanitizer\` should either not have a default implementation, or have a secure one. Otherwise, the default implementation will create a false sense of security, and many will unwittingly use it without knowing that it only supplies a very basic level of protection.
> 
> Putting a warning in the documentation won't necessarily help much, because it might have been introduced into the codebase by somebody else, and the developer is just following pattern, or they just found it in some search result.
