a2ui-project / a2ui-project/a2ui

[BUG]: Default text renderer in the a2a-chat-canvas sample bypasses Angular HTML sanitization

未关闭
#2,294 2 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
P2 status: first-line-handled
主要语言
TypeScript
星标
16.4k
派生
1.3k
平均合并
2 天 13 小时
30 天内合并 PR
134

描述

# Default text renderer in the a2a-chat-canvas sample bypasses Angular HTML sanitization

Repository: https://github.com/a2ui-project/a2ui (sample project `samples/community/client/angular/projects/a2a-chat-canvas`, v0.0.1)
CWE: CWE-79 (Improper Neutralization of Input During Web Page Generation — XSS)

## Summary

The default implementation of the chat canvas's text-part renderer returns `sanitizer.bypassSecurityTrustHtml()`, and the component binds the result via `@HostBinding('innerHTML')`. Remote agent text parts are therefore rendered as raw HTML inside the host application's origin. The class does not actually render markdown; it passes the original HTML through.

## Affected code

- `samples/community/client/angular/projects/a2a-chat-canvas/src/lib/services/sanitizer-markdown-renderer-service.ts:29`
- Rendered at `default-text-part.ts:60-71` (`@HostBinding('innerHTML')`)
- Wired as the default by `markdown-renderer-service.ts:31-36` and `config.ts:103`

## Observed behavior

An agent message containing `` executes in the host page (standard stored-XSS consequence of the SafeHtml bypass).

## Context

This is community sample code (v0.0.1), not an official npm release; it is filed because the unsafe renderer is the default configuration of the sample, so applications copying the sample inherit the behavior as-is.

## Suggested remediation

Make a sanitizing pipeline the default renderer — e.g. the `@a2ui/markdown-it` path used elsewhere (markdown-it with `html: false` + DOMPurify).

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。