software-mansion / software-mansion/TypeGPU
Vulnerability in TypeGPU project
Nobody has claimed this yet.
- Dominant language
- TypeScript
- Stars
- 3.2k
- Forks
- 122
- Avg merge
- 3d 5h
- Merged PRs (30d)
- 34
Description
While working on TypeGPU project, I scanned the dependency manifest and found that it uses a vulnerable version of dompurify. The scan revealed a URI validation bypass issue where custom attribute predicates can skip protocol checks, potentially allowing unsafe values like javascript: to pass through sanitization and lead to DOM-based XSS.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Inspect the dependency manifest mentioned in the issue and confirm the installed dompurify version against the linked CVE report. Update the vulnerable dependency to a patched version, then run the repository's existing checks and verify that the dependency scan no longer reports this vulnerability.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- typescript
- Domain
- security
- Issue type
- Bug
- Difficulty
- 2/5
- Estimated time
- 1-3 hours
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 62/100