Skip to content

fix(core): prevent CSS injection via rule-breaking declaration values - #5319

Merged
antfu merged 1 commit into
unocss:mainfrom
antfubot:fix/bracket-css-injection
Sep 8, 2026
Merged

antfu merged 1 commit into
unocss:mainfrom
antfubot:fix/bracket-css-injection

Conversation

@antfubot

@antfubot antfubot commented Sep 8, 2026 •

Copy link
Copy Markdown
Contributor

Closes #5300.

When UnoCSS scans untrusted, user-generated content, a value that contains {/} can close its own rule and open a new one, injecting arbitrary CSS. Two vectors from the report both hit the same serialization point (entriesToCss, ${key}:${value};):

  • Arbitrary bracket value: w-[100px;}body{background:red}]
  • Poisoned theme value: colors.custom = 'red;}body{background:red}' → text-custom

Both produced:

.text-custom{color:red;}body{background:red};}

Rather than patching one handler, the guard lives in core's entriesToCss, which every rule body funnels through, so it covers arbitrary values, theme values, and custom rules alike. A declaration whose value contains a top-level { or } (outside a quoted string) is dropped.

Only {/} are rejected, not ;: cross-rule injection requires opening a new block, whereas a lone ; only appends declarations to the same selector (no escalation) and appears in legitimate output (e.g. preset-wind4's bg-conic-*). Quoted strings are respected, so content-["a;b{c}"] still works.

The playground/config parts of the report are the sandbox behaving as designed (you author your own HTML/config), so this change targets the library-level injection.

This PR was created with the help of an agent.

@antfubot
antfubot requested review from antfu and zyyv as code owners September 8, 2026 04:52
@netlify

netlify Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for unocss ready!

Built without sensitive environment variables

Name Link
🔨 Latest commit a58be9d
🔍 Latest deploy log https://app.netlify.com/projects/unocss/deploys/6a9f986180bb1e0009edaa9b
😎 Deploy Preview https://deploy-preview-5319--unocss.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.
🤖 Make changes Run an agent on this branch

To edit notification comments on pull requests, go to your Netlify project configuration.

@pkg-pr-new

pkg-pr-new Bot commented Sep 8, 2026 •

Copy link
Copy Markdown

Open in StackBlitz

commit: a58be9d

@antfubot
antfubot force-pushed the fix/bracket-css-injection branch from e699cda to a58be9d Compare September 8, 2026 05:08
@antfubot antfubot changed the title fix(preset-mini): prevent CSS injection via arbitrary bracket values fix(core): prevent CSS injection via rule-breaking declaration values Sep 8, 2026
@antfu
antfu enabled auto-merge September 8, 2026 05:10
@antfu
antfu added this pull request to the merge queue Sep 8, 2026
Merged via the queue into unocss:main with commit e2221f2 Sep 8, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security Vulnerability: URL Parameter XSS + CSS Injection (CVE Request)

2 participants

Sponsor
SponsoredKunjungi sekarang
Promo