GHSA-8j5q-mfj2-5q9q
@astrojs/rss: XML Injection via Unescaped RSS Feed Fields
빠른 조치
GHSA-8j5q-mfj2-5q9q — @astrojs/rss: 아래 명령으로 수정 버전으로 올리세요.
npm install @astrojs/rss@4.0.19 상세
## Summary
In `@astrojs/rss`, the `source.title` and `enclosure.type` item fields are interpolated directly into XML template strings without XML-character escaping before being parsed by `fast-xml-parser`. An attacker who controls these field values can inject arbitrary XML elements into the generated RSS feed.
## Details
Two fields in `packages/astro-rss/src/index.ts` are affected:
### `source.title`
```typescript item.source = parser.parse( `<source url="${result.source.url}">${result.source.title}</source>`, ).source; ```
`source.title` is validated only as `z.string()`, with no restriction on XML special characters. A value containing `</source>` followed by arbitrary XML is parsed as real XML elements, merging injected nodes into the RSS item.
### `enclosure.type`
```typescript item.enclosure = parser.parse( `<enclosure url="${enclosureURL}" length="${result.enclosure.length}" type="${result.enclosure.type}"/>`, ).enclosure; ```
`enclosure.type` is also `z.string()` and is interpolated into an XML attribute without escaping. A value containing `"` followed by additional XML can break out of the attribute and inject extra elements.
## Proof of Concept
`source.title` injection:
```javascript source: { url: 'https://legit.example.com', title: '</source><item><title>INJECTED</title><link>https://evil.com</link></item><source>', } // Result: RSS feed contains an injected <item> element with an evil.com link ```
`enclosure.type` injection:
```javascript enclosure: { url: 'https://example.com/a.mp3', length: 0, type: 'audio/mpeg" /><link>https://evil.example.com</link><enclosure fake="', } // Result: RSS feed contains an injected <link> element ```
Both injections were confirmed with `fast-xml-parser`: the injected `"link": "https://evil.com"` appears in the parsed output.
## Impact
An attacker who can control `source.title` or `enclosure.type` values (e.g., via a CMS, database, or user-submitted content that populates `RSSFeedItem`) can inject arbitrary XML into the generated RSS feed. This corrupts feed structure, injects false metadata (e.g., a fake `<link>` pointing to a malicious URL), and can cause feed readers to misparse or display attacker-controlled content. In SSR mode (`output: 'server'`), the poisoned feed is served on every request to all subscribers.
## Patches
Fixed in `@astrojs/rss@4.0.19`.
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
참고
- https://github.com/withastro/astro/security/advisories/GHSA-8j5q-mfj2-5q9q [WEB]
- https://github.com/withastro/astro/pull/17209 [WEB]
- https://github.com/withastro/astro/commit/fbcfa039dfe3d700b239f595a6c55ee35e45bd06 [WEB]
- https://github.com/withastro/astro [PACKAGE]
- https://github.com/withastro/astro/releases/tag/@astrojs/rss@4.0.19 [WEB]