fix(core): prevent CSS injection via rule-breaking declaration values - #5319
Merged
Merged
Conversation
✅ Deploy Preview for unocss ready!Built without sensitive environment variables
To edit notification comments on pull requests, go to your Netlify project configuration. |
|
commit: |
antfu
approved these changes
Sep 8, 2026
antfubot
force-pushed
the
fix/bracket-css-injection
branch
from
September 8, 2026 05:08
e699cda to
a58be9d
Compare
antfu
enabled auto-merge
September 8, 2026 05:10
6 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #5300.
When UnoCSS scans untrusted, user-generated content, a value that contains
{/}can close its own rule and open a new one, injecting arbitrary CSS. Two vectors from the report both hit the same serialization point (entriesToCss,${key}:${value};):w-[100px;}body{background:red}]colors.custom = 'red;}body{background:red}'→text-customBoth produced:
Rather than patching one handler, the guard lives in core's
entriesToCss, which every rule body funnels through, so it covers arbitrary values, theme values, and custom rules alike. A declaration whose value contains a top-level{or}(outside a quoted string) is dropped.Only
{/}are rejected, not;: cross-rule injection requires opening a new block, whereas a lone;only appends declarations to the same selector (no escalation) and appears in legitimate output (e.g.preset-wind4'sbg-conic-*). Quoted strings are respected, socontent-["a;b{c}"]still works.The playground/config parts of the report are the sandbox behaving as designed (you author your own HTML/config), so this change targets the library-level injection.
This PR was created with the help of an agent.