IntersectMBO / IntersectMBO/evolution-sdk
blueprint/Codegen: escape blueprint-controlled strings in generated TypeScript
- Dominant language
- TypeScript
- Stars
- 22
- Forks
- 30
- Avg merge
- 5h 29m
- Merged PRs (30d)
- 12
Description
## Summary
blueprint/Codegen.ts generateTypeScript() splices blueprint strings into generated
TypeScript without escaping, so a crafted blueprint can inject statements into the
output that run when a consumer builds or imports the generated file. Only reachable
when codegen runs over an untrusted blueprint (e.g. a third party's plutus.json);
self-authored blueprints are unaffected. generateTypeScript returns a string and
executes nothing itself.
## Affected
packages/evolution/src/blueprint/Codegen.ts
- L907 preamble.title in the header JSDoc (`*/` breaks out)
- L1092-1094 validator.title / hash / compiledCode as raw string literals
- L248, L419, L606, L649 constructor tag in TSchema.Literal / TSchema.TaggedStruct
- L286, L448, L525, L600, L645 field title used as an object property name, unquoted
- L959-963, L1018-1023, L1059-1064, L1087-1090 title/description in JSDoc
entry: blueprint/index.ts exports Codegen.generateTypeScript (public via @evolution-sdk/evolution/blueprint).
## Fix
- string literals (title, hash, compiledCode, tag): emit with JSON.stringify, not "${value}".
- property names (field titles): validate as identifier, else quote with JSON.stringify.
- JSDoc (title, description, header): strip `*/`, or drop untrusted strings from comments.
## Regression test
- given: preamble.title = `x */\nglobalThis.__pwned = 1\n/*`, validator title/hash/compiledCode with `"` and a newline
- before: output contains the injected statement outside any comment/string
- after: every value stays inside its intended comment or literal
Must FAIL on main, PASS after the fix.
## Reference
GHSA-79p9-vmph-w58f
Contributor guide
Assessment
This issue has not been assessed yet.