From cfcff7084eb01c8a484d982b1def12745ec6af45 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Wed, 15 Jul 2026 11:28:53 -1000 Subject: Escape non-markdown readmes without a filter A readme that is not markdown was written to the about page as raw HTML when no about-filter was configured, so an untrusted repository could inject script. --- source/ui-summary.c | 18 ++++++++++++++++-- 1 file changed, 16 insertions(+), 2 deletions(-) (limited to 'source/ui-summary.c') diff --git a/source/ui-summary.c b/source/ui-summary.c index 7e533e1..471f0c9 100644 --- a/source/ui-summary.c +++ b/source/ui-summary.c @@ -157,9 +157,23 @@ void cgit_print_repo_readme(const char *path) strbuf_release(&sb); } html(""); + } else if (!ctx.repo->about_filter) { + /* No about-filter is configured, so there is nothing to turn + * the readme source into safe HTML. Escape it rather than serve + * repo content raw, which would let an untrusted repository + * inject script into the about page. + */ + if (ref) { + cgit_print_file(filename, ref, 1, 1); + } else { + struct strbuf sb = STRBUF_INIT; + if (strbuf_read_file(&sb, filename, 0) >= 0) + html_txt(sb.buf); + strbuf_release(&sb); + } } else { - /* Otherwise print the readme through the about-filter, or raw - * when none is configured. + /* An about-filter is configured and is responsible for turning + * the source into safe HTML, so pass it through the filter raw. */ cgit_open_filter(ctx.repo->about_filter, filename); if (ref) -- cgit v2.8.0