Skip to content

ATLAS-5298: Atlas-React UI: Fix Critical XSS Vulnerability in sanitiz…#641

Open
Brijesh619 wants to merge 1 commit into
apache:masterfrom
Brijesh619:ATLAS-5298
Open

ATLAS-5298: Atlas-React UI: Fix Critical XSS Vulnerability in sanitiz…#641
Brijesh619 wants to merge 1 commit into
apache:masterfrom
Brijesh619:ATLAS-5298

Conversation

@Brijesh619
Copy link
Copy Markdown
Contributor

What changes were proposed in this pull request?
Upgraded sanitize-html dependency from 2.13.0 to 2.17.4
Fixed critical XSS vulnerability reported in npm audit
Addressed security issue related to unsafe raw-text passthrough handling (xmp tag)
Verified compatibility with existing rich text rendering and sanitization flows
No functional business logic changes were introduced

Related vulnerability:

GHSA-rpr9-rxv7-x643
How was this patch tested?
Manual Testing

Validated rich text editor and HTML rendering flows across the application:

Classification form
Glossary form
Business Metadata form
BM Attributes fields
HTML renderer components
Show more text components
Security Validation

Tested sanitization against malicious HTML payloads:

<script>alert('xss')</script>

<img src=x onerror=alert('xss')>
<xmp><script>alert('xss')</script></xmp>

Verified:

scripts are removed/sanitized correctly
no JavaScript execution occurs
formatting and existing rich text rendering continue to work as expected
Additional Validation
Executed npm audit after dependency upgrade
Verified application builds successfully
Performed regression testing for ReactQuill editor content rendering and display flows

@Brijesh619
Copy link
Copy Markdown
Contributor Author

Screenshot from 2026-05-21 15-35-54

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant