Skip to content

fix: harden ZIP paths, XML names, and property copying - #222

Merged
ghiscoding merged 1 commit into
mainfrom
bugfix/security-audit
Oct 4, 2026
Merged

ghiscoding merged 1 commit into
mainfrom
bugfix/security-audit

Conversation

@ghiscoding

@ghiscoding ghiscoding commented Oct 4, 2026 •

Copy link
Copy Markdown
Owner

Summary

Prevent unsafe archive paths, XML markup injection through names, and local prototype manipulation in packages/excel-builder-vanilla.

Why

Caller-controlled filenames, style keys, and selected object properties could alter generated output or object prototypes. These are conditional risks; no host filesystem write, spreadsheet code execution, or global prototype pollution was demonstrated.

Changes

  • Validate ZIP paths centrally for normal and streaming exports, including custom exporters.
  • Reject markup delimiters in XML names during serialization and reserved attribute names when setting attributes.
  • Safely copy own properties in pick(), including __proto__, while supporting null-prototype objects.
  • Preserve existing alignment attributes, Unicode names, and namespaced XML attributes.
  • Document validation behavior and audit findings.

Net physical LOC against the pre-security baseline, including comments and blank lines:

Category Change
Production source +15
Tests +141
Total, excluding documentation +156

Runtime changes are limited to three files, with no new dependencies, API removals, or deprecations.

Validation

  • 328 tests passed across 25 files.
  • 100% line, statement, and function coverage; 93.77% branch coverage.
  • Library TypeScript check, scoped Biome check, JavaScript build, and git diff --check passed.

Comments

Unsafe ZIP paths now fail during export rather than in addMedia(). Unsafe XML names fail during serialization; reserved XML attribute names fail in setAttribute().

These checks do not validate the complete OOXML schema or sanitize custom XML strings. Performance benchmarks and Excel/LibreOffice application checks were not run for this patch.

AI / LLM assistance

  • AI / LLM assistance used:
    • No
    • Yes
  • Tool/model: OpenAI Codex ChatGPT 6 Astra.
  • How used: Source review, implementation, regression tests, validation, and documentation.

Checklist

  • The changes are limited to only one scope: library security hardening and its supporting tests/documentation.
  • Tests were added or updated where appropriate.
  • Documentation was updated where appropriate.

@codecov

codecov Bot commented Oct 4, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.0%. Comparing base (8123ba6) to head (74c8ff0).

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #222   +/-   ##
=======================================
  Coverage   100.0%   100.0%           
=======================================
  Files          27       27           
  Lines        1867     1877   +10     
  Branches      404      409    +5     
=======================================
+ Hits         1867     1877   +10     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@ghiscoding
ghiscoding merged commit 3e58732 into main Oct 4, 2026
7 checks passed
@ghiscoding
ghiscoding deleted the bugfix/security-audit branch October 4, 2026 18:51
@github-actions

github-actions Bot commented Oct 4, 2026

Copy link
Copy Markdown

🎉 This pull request is included in version 5.3.0 📦
🔗 The release notes are available at: GitHub Release 🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant