software-mansion / software-mansion/TypeGPU

Vulnerability in TypeGPU project

Open Beginner friendly
#2,351 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
TypeScript
Stars
3.2k
Forks
122
Avg merge
3d 5h
Merged PRs (30d)
34

Description

While working on TypeGPU project, I scanned the dependency manifest and found that it uses a vulnerable version of dompurify. The scan revealed a URI validation bypass issue where custom attribute predicates can skip protocol checks, potentially allowing unsafe values like javascript: to pass through sanitization and lead to DOM-based XSS.

CVE Report
CVE Link

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Inspect the dependency manifest mentioned in the issue and confirm the installed dompurify version against the linked CVE report. Update the vulnerable dependency to a patched version, then run the repository's existing checks and verify that the dependency scan no longer reports this vulnerability.

Written by the indexing model from the issue text.

Assessment

Tech stack
typescript
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
62/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.