a2ui-project / a2ui-project/a2ui

[BUG]: Default text renderer in the a2a-chat-canvas sample bypasses Angular HTML sanitization

Open
#2,294 2 comments 0 reactions 0 assignees View on GitHub
P2 status: first-line-handled
Dominant language
TypeScript
Stars
16.4k
Forks
1.3k
Avg merge
2d 13h
Merged PRs (30d)
134

Description

# Default text renderer in the a2a-chat-canvas sample bypasses Angular HTML sanitization

Repository: https://github.com/a2ui-project/a2ui (sample project `samples/community/client/angular/projects/a2a-chat-canvas`, v0.0.1)
CWE: CWE-79 (Improper Neutralization of Input During Web Page Generation — XSS)

## Summary

The default implementation of the chat canvas's text-part renderer returns `sanitizer.bypassSecurityTrustHtml()`, and the component binds the result via `@HostBinding('innerHTML')`. Remote agent text parts are therefore rendered as raw HTML inside the host application's origin. The class does not actually render markdown; it passes the original HTML through.

## Affected code

- `samples/community/client/angular/projects/a2a-chat-canvas/src/lib/services/sanitizer-markdown-renderer-service.ts:29`
- Rendered at `default-text-part.ts:60-71` (`@HostBinding('innerHTML')`)
- Wired as the default by `markdown-renderer-service.ts:31-36` and `config.ts:103`

## Observed behavior

An agent message containing `` executes in the host page (standard stored-XSS consequence of the SafeHtml bypass).

## Context

This is community sample code (v0.0.1), not an official npm release; it is filed because the unsafe renderer is the default configuration of the sample, so applications copying the sample inherit the behavior as-is.

## Suggested remediation

Make a sanitizing pipeline the default renderer — e.g. the `@a2ui/markdown-it` path used elsewhere (markdown-it with `html: false` + DOMPurify).

Contributor guide

Open the contributing guide

Research direction

Examine the files mentioned: sanitizer-markdown-renderer-service.ts, default-text-part.ts, markdown-renderer-service.ts, and config.ts. Understand how the default text renderer bypasses Angular's sanitization. The fix involves replacing the bypass with a safe pipeline, possibly using @a2ui/markdown-it with html: false and DOMPurify. Test by creating a message with an XSS payload and verifying it no longer executes.

Written by the indexing model from the issue text.

Assessment

Tech stack
angular, typescript
Domain
frontend, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Active
Clarity
Clearly specified
Newbie friendliness
65/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.