IntersectMBO / IntersectMBO/evolution-sdk

blueprint/Codegen: escape blueprint-controlled strings in generated TypeScript

Open
#412 0 comments 0 reactions 0 assignees View on GitHub
bug external-review
Dominant language
TypeScript
Stars
22
Forks
30
Avg merge
5h 29m
Merged PRs (30d)
12

Description

## Summary
blueprint/Codegen.ts generateTypeScript() splices blueprint strings into generated
TypeScript without escaping, so a crafted blueprint can inject statements into the
output that run when a consumer builds or imports the generated file. Only reachable
when codegen runs over an untrusted blueprint (e.g. a third party's plutus.json);
self-authored blueprints are unaffected. generateTypeScript returns a string and
executes nothing itself.

## Affected
packages/evolution/src/blueprint/Codegen.ts
- L907 preamble.title in the header JSDoc (`*/` breaks out)
- L1092-1094 validator.title / hash / compiledCode as raw string literals
- L248, L419, L606, L649 constructor tag in TSchema.Literal / TSchema.TaggedStruct
- L286, L448, L525, L600, L645 field title used as an object property name, unquoted
- L959-963, L1018-1023, L1059-1064, L1087-1090 title/description in JSDoc

entry: blueprint/index.ts exports Codegen.generateTypeScript (public via @evolution-sdk/evolution/blueprint).

## Fix
- string literals (title, hash, compiledCode, tag): emit with JSON.stringify, not "${value}".
- property names (field titles): validate as identifier, else quote with JSON.stringify.
- JSDoc (title, description, header): strip `*/`, or drop untrusted strings from comments.

## Regression test
- given: preamble.title = `x */\nglobalThis.__pwned = 1\n/*`, validator title/hash/compiledCode with `"` and a newline
- before: output contains the injected statement outside any comment/string
- after: every value stays inside its intended comment or literal
Must FAIL on main, PASS after the fix.

## Reference
GHSA-79p9-vmph-w58f

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.