Skip to content

fix: route image directive src through safe_url - #442

Merged
lepture merged 1 commit into
lepture:mainfrom
Gares95:harden-image-directive-src
May 26, 2026
Merged

fix: route image directive src through safe_url#442
lepture merged 1 commit into
lepture:mainfrom
Gares95:harden-image-directive-src

Conversation

@Gares95

@Gares95 Gares95 commented May 24, 2026

Copy link
Copy Markdown
Contributor

The inline image renderer (HTMLRenderer.image) routes src through safe_url, but the image/figure directive's render_block_image renders src with escape_text only. As a result .. image:: javascript:alert produced <img src="javascript:alert">, inconsistent with the inline ![alt](javascript:...) path which yields src="#harmful-link".

This is not a known exploit (javascript: in does not execute in current browsers), but the directive should match the renderer's link/image safety contract so the two paths cannot drift.

  • render_block_image now calls self.safe_url(src); this is a drop-in for the previous escape_text(src) on any non-harmful scheme (safe_url returns escape_text(url) in that case) and maps harmful schemes to #harmful-link.
  • Add behaviour-pinning tests for harmful/encoded/safe scheme variants across inline links, reference links, and the image directive.

The inline image renderer (HTMLRenderer.image) routes src through
safe_url, but the image/figure directive's render_block_image renders
src with escape_text only. As a result `.. image:: javascript:alert`
produced `<img src="javascript:alert">`, inconsistent with the inline
`![alt](javascript:...)` path which yields `src="#harmful-link"`.

This is not a known exploit (javascript: in <img src> does not execute
in current browsers), but the directive should match the renderer's
link/image safety contract so the two paths cannot drift.

- render_block_image now calls self.safe_url(src); this is a drop-in for
  the previous escape_text(src) on any non-harmful scheme (safe_url
  returns escape_text(url) in that case) and maps harmful schemes to
  #harmful-link.
- Add behaviour-pinning tests for harmful/encoded/safe scheme variants
  across inline links, reference links, and the image directive.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
@sonarqubecloud

Copy link
Copy Markdown

@codecov

codecov Bot commented May 25, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 91.70%. Comparing base (067f908) to head (5afeaf6).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #442   +/-   ##
=======================================
  Coverage   91.70%   91.70%           
=======================================
  Files          34       34           
  Lines        2639     2639           
  Branches      430      430           
=======================================
  Hits         2420     2420           
  Misses        147      147           
  Partials       72       72           
Flag Coverage Δ
unittests 91.66% <100.00%> (ø)

Flags with carried forward coverage won't be shown. Click here to find out more.

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@lepture
lepture merged commit 5f4ce24 into lepture:main May 26, 2026
24 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants