Files
ComfyAssets-ComfyUI-KikoTools/web
Vito Sansevero 0c69abc829 fix: improve regex pattern to detect script tag bypass attempts
Improved the HTML filtering regex to properly detect all variations of
script tags including bypass attempts with whitespace before the closing
bracket (e.g., '<script >' and '</script >').

Changed from word boundary pattern /<script\b/gi to a more comprehensive
pattern /<\s*\/?script[^>]*>/gi that matches:
- Optional whitespace after opening bracket
- Optional forward slash for closing tags
- Any characters until closing bracket (catches attributes and whitespace)

This fixes the CodeQL security alert for bad HTML filtering regexp that
could be bypassed with malformed tags.

Also updated iframe, embed, and object tag patterns for consistency.
2025-10-05 07:29:41 -07:00
..