T09 · Insecure Skill Coding Practices
- Location
docsify-server/index.html:75- Finding
Cross-Origin Markdown Route Can Inject Active HTML into the Viewer Origin
- Content
View full analysis
Vulnerability Details
File Location:
docsify-server/index.html:75-80;docsify-server/assets/docsify.min.js:1
Vulnerability Type: Cross-origin active-content injection
Risk Level: MediumRelevant code snippets:
From
docsify-server/index.html:75-80:javascript search: { maxAge: 0, paths: [location.hash.replace(/^#/, "").split("?")[0] || "/"], placeholder: "Search", noData: "No results found",Relevant portions of the bundled Docsify implementation in
docsify-server/assets/docsify.min.js:1:javascript function R(e){return/(:|(\/{2}))/g.test(e)}javascript e=R(e)?e:q(a,e)javascript function X(t,e,n){ ... r=new XMLHttpRequest, ... r.open("GET",t), ... r.send() }javascript sanitize:!1javascript function w(e,n){ return e=v.createElement(e),n&&(e.innerHTML=n),e }Technical Analysis
The page derives a Docsify document path from the URL fragment. The bundled router recognizes paths containing a scheme or protocol-relative syntax as remote paths and preserves them rather than constraining them to the deployed bucket.
Docsify subsequently retrieves that path with
XMLHttpRequest. If the remote server permits cross-origin reads through CORS, an unrelated content provider can supply the Markdown document rendered by the viewer.The bundled Markdown configuration has sanitization disabled (
sanitize:!1) and uses HTML DOM insertion. Consequently, active HTML accepted by the Markdown renderer, including event-handler attributes, can execute in the origin of the deployed viewer. This is distinct from ordinary publication of user-selected Markdown: the triggering URL can identify content hosted and controlled by an independent attacker.No evidence indicates that the project author intentionally introduced this behavior for attack purposes. It is therefore classified as an exploitable c ...[truncated 1601 chars]
- Remediation
View remediation
Remediation Suggestions
- Reject absolute and protocol-relative Docsify routes before document retrieval. Permit only normalized, same-origin paths.
- Restrict document routes to the expected
/md-web/object prefix and reject schemes, backslashes, encoded traversal sequences, and paths outside that prefix. - Enable robust HTML sanitization with an allowlist-based sanitizer before inserting rendered Markdown into the DOM.
- Prefer disabling raw HTML in Markdown if the feature is not required.
- Apply a restrictive Content Security Policy that disallows inline scripts and event handlers, for example by omitting
unsafe-inlinefromscript-src. - Add regression tests covering absolute URLs, protocol-relative URLs, encoded route variants, raw HTML, event-handler attributes, and dangerous URL schemes.
- Consider isolating the document viewer on a dedicated origin that does not host authenticated applications or sensitive browser storage.
