From 134e36343ef57ed7e6e2b3bb9e7f05ad37865794 Mon Sep 17 00:00:00 2001 From: Ben McCann <322311+benmccann@users.noreply.github.com> Date: Sun, 24 Nov 2024 21:36:56 -0800 Subject: [PATCH] fix: ensure error messages are escaped (#13050) --- .changeset/fast-swans-perform.md | 5 +++++ packages/kit/src/exports/vite/dev/index.js | 3 ++- packages/kit/src/runtime/server/utils.js | 3 ++- 3 files changed, 9 insertions(+), 2 deletions(-) create mode 100644 .changeset/fast-swans-perform.md diff --git a/.changeset/fast-swans-perform.md b/.changeset/fast-swans-perform.md new file mode 100644 index 000000000000..f20bd74d6924 --- /dev/null +++ b/.changeset/fast-swans-perform.md @@ -0,0 +1,5 @@ +--- +'@sveltejs/kit': patch +--- + +fix: ensure error messages are escaped diff --git a/packages/kit/src/exports/vite/dev/index.js b/packages/kit/src/exports/vite/dev/index.js index 0dbc912940a2..23c0fae2eeb0 100644 --- a/packages/kit/src/exports/vite/dev/index.js +++ b/packages/kit/src/exports/vite/dev/index.js @@ -18,6 +18,7 @@ import { compact } from '../../../utils/array.js'; import { not_found } from '../utils.js'; import { SCHEME } from '../../../utils/url.js'; import { check_feature } from '../../../utils/features.js'; +import { escape_html } from '../../../utils/escape.js'; const cwd = process.cwd(); @@ -508,7 +509,7 @@ export async function dev(vite, vite_config, svelte_config) { const error_template = ({ status, message }) => { return error_page .replace(/%sveltekit\.status%/g, String(status)) - .replace(/%sveltekit\.error\.message%/g, message); + .replace(/%sveltekit\.error\.message%/g, escape_html(message)); }; res.writeHead(500, { diff --git a/packages/kit/src/runtime/server/utils.js b/packages/kit/src/runtime/server/utils.js index f211739140e1..473804cf9183 100644 --- a/packages/kit/src/runtime/server/utils.js +++ b/packages/kit/src/runtime/server/utils.js @@ -5,6 +5,7 @@ import { negotiate } from '../../utils/http.js'; import { HttpError } from '../control.js'; import { fix_stack_trace } from '../shared-server.js'; import { ENDPOINT_METHODS } from '../../constants.js'; +import { escape_html } from '../../utils/escape.js'; /** @param {any} body */ export function is_pojo(body) { @@ -50,7 +51,7 @@ export function allowed_methods(mod) { * @param {string} message */ export function static_error_page(options, status, message) { - let page = options.templates.error({ status, message }); + let page = options.templates.error({ status, message: escape_html(message) }); if (DEV) { // inject Vite HMR client, for easier debugging