Unvalidated Output Injection
- Category
- Output Handling
- Confidence
- 65% confidence
- Finding
Model output is used without validation or sanitization. Unvalidated output injected into downstream contexts (SQL, shell, HTML) enables injection attacks and arbitrary code execution.
- Content
md - **noindex**: `robots: { index: false, follow: true }`. - **Sitemap / robots**: `app/sitemap.ts` (returns `MetadataRoute.Sitemap`) and `app/robots.ts` (returns `MetadataRoute.Robots`, including `sitemap: "https://example.com/sitemap.xml"`). - **OG image**: `app/opengraph-image.tsx` (or per route segment) using `ImageResponse` from `next/og`. - **JSON-LD**: in the page component, `<script type="application/ld+json" dangerouslySetInnerHTML={{ __html: JSON.stringify(data).replace(/</g, "\\u003c") }} />`. - **llms.txt**: `public/llms.txt`, or `app/llms.txt/route.ts` returning `text/plain` if it should be generated. - **lang**: `<html lang="en">` in the root layout.
