Repository navigation
Conversation
Harden `getPageData()` against DOM clobbering. `document.getElementById()` returns the first element with the id regardless of tag, so an element with a colliding id could shadow the legitimate `<script>` and feed attacker-controlled JSON into the parse. Select `script[id="wp-script-module-data-ai-wp-admin"]`, return the existing fallback when the result is not an `HTMLScriptElement`, and read its non-null `text`. Behavior is unchanged for the normal case. This is defense-in-depth: the AI home admin screen does not render lower-privilege user content, so there is no known injection vector, and the parsed data only feeds React-escaped output. Hardened for consistency with the other Script Module data reads. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
The following accounts have interacted with this PR and/or linked issues. I will continue to update these lists as activity occurs. You can also manually ask me to refresh this list by adding the If you're merging code through a pull request on GitHub, copy and paste the following into the bottom of the merge commit message. To understand the WordPress project's expectations around crediting contributors, please review the Contributor Attribution page in the Core Handbook. |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## develop #991 +/- ##
==========================================
Coverage 75.18% 75.18%
Complexity 3227 3227
==========================================
Files 133 133
Lines 12488 12488
==========================================
Hits 9389 9389
Misses 3099 3099
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
What?
Harden
getPageData()against DOM clobbering.document.getElementById()returns the first element with the id regardless of tag, so an element with a colliding id could shadow the legitimate<script>and feed attacker-controlled JSON into the parse.Select
script[id="wp-script-module-data-ai-wp-admin"], return the existing fallback when the result is not anHTMLScriptElement, and read its non-nulltext. Behavior is unchanged for the normal case.This is defense-in-depth: the AI home admin screen does not render lower-privilege user content, so there is no known injection vector, and the parsed data only feeds React-escaped output. Hardened for consistency with the other Script Module data reads.
Why?
See the corresponding changes in:
How?
Use of AI Tools
AI assistance: Yes
Tool(s): Claude Code
Model(s): Claude Opus 4.8
Used for: Applying fix from core to the AI plugin.
Testing Instructions
Changelog Entry