app/util.go imports text/template. Nothing interpolated is escaped: the
search query in static/html/search.htm and head.htm, and every DA
username, title and description written by DeviationList,
ParseComments, BuildUserPlate and ParseDescription. The CSP blocks
scripts but not markup, inline styles, meta refresh or injected forms; any
title containing < corrupts the page.
Fix: switch to html/template; wrap the pre-built HTML fragments in
template.HTML; escape strings in the Go builders with
html.EscapeString and attribute-escape URLs. Add tests that a query and a
title containing "><b> render as text.
Land before other template work.
Roadmap item 2.1, size M. See ROADMAP.md.
closed by commit 35d16226b9 by cmc: Escape everything rendered from user or DeviantArt input
2026-09-11 15:13 UTC