Skip to content

fix: add URL validation in templateLoader.js (CWE-918) - #30

Open
anupamme wants to merge 4 commits into
Mountea-Framework:devfrom
anupamme:fix-repo-mounteadialoguer-cwe-918-template-url-allowlist
Open

anupamme wants to merge 4 commits into
Mountea-Framework:devfrom
anupamme:fix-repo-mounteadialoguer-cwe-918-template-url-allowlist

Conversation

@anupamme

@anupamme anupamme commented Oct 6, 2026

Copy link
Copy Markdown

The template loader validates URLs against an allowlist but has security gaps: same-origin URLs bypass validation entirely, and URL parsing uses the page's location as base which could be manipulated. An attacker who controls configuration could provide malicious URLs that pass validation. The affected code is src/lib/onboarding/templateLoader.js:23. This change is the fix I would apply.

Reference: CWE-918

What changed

  • src/lib/onboarding/templateLoader.js

Verification

No automated check could be run against this repository, so this change is unverified beyond review. Please treat it as a suggestion.


Automated security fix by OrbisAI Security

pavlicekdominik and others added 4 commits April 19, 2026 18:57
Fix: Fixing import/example dialogue audio files
Fix: Fixing imports for projects, dialogues, nodes
Automated security fix generated by OrbisAI Security
@netlify

netlify Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

✅ Deploy Preview for mountea-dialoguer ready!

Name Link
🔨 Latest commit 25b8ca3
🔍 Latest deploy log https://app.netlify.com/projects/mountea-dialoguer/deploys/6ac4adf4a0faca0008d326d9
😎 Deploy Preview https://deploy-preview-30--mountea-dialoguer.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 complexity · 0 duplication

Metric Results
Complexity 0
Duplication 0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants