lud

lud

Oaskit 0.14.1 - security release

Hello everyone,

This is a security update for Oaskit. Version 0.14.1 is now on Hex and fixes a reflected cross-site scripting (XSS) vulnerability in the default error handler.

If you are using Oaskit you should upgrade now.

Following the recent effort of scanning libraries with Claude Code and Fable I found a vulnerability in one of my libraries. I will do the same for JSV later.

What was affected

Oaskit’s default error handler (Oaskit.ErrorHandler.Default) can render validation errors as an HTML page when a request’s Accept header contains html. This is enabled by default (html_errors: true) and is genuinely handy in development for reading errors straight from the browser.

The problem: request-controlled values (such as object keys from a request body or query parameter, or a malformed Content-Type) were written into that HTML page without escaping. A crafted link to a validating endpoint could execute JavaScript in the application’s origin, a plain GET navigation is enough, no form or special headers required. Dumb me yeah.

Severity is Medium (CVSS 6.1). The full write-up is in the advisory:

:right_arrow: GHSA-h7xw-x8wr-xpcc

The HTML error page stays on by default, because it’s useful in dev and all interpolated values are now HTML-escaped.

Who should upgrade

All versions before 0.14.1 are affected. If you use Oaskit, please bump:

{:oaskit, "~> 0.14.1"}

Workaround (if you can’t upgrade right away)

Disable HTML error rendering so only JSON errors are returned:

plug Oaskit.Plugs.ValidateRequest, html_errors: false

Apologies for the churn this upgrade causes, and for shipping the issue in the first place.

Thank you for using Oaskit! If you find anything suspicious, please report privately via the repository’s Security tab.

(@AstonJ does that still merge into the main library thread?)

First Post! Switch mode

AstonJ

AstonJ

Now that any library/project can get one of our new forums we no longer need to merge the threads :icon_biggrin: however if you’d like a reference to updates like this in the main thread then simply link to the main thread like you have - it will then show in the footer of the post:

Btw if you want an easier way to set up one of our new forums (for Oaskit or any other library) you can just give provide the data as Rails create block, we can add it to our seed file and then set you up with the admin thread. Just PM me if you want to do it that way :023:

— All posts loaded —

Where Next?

Trending in News & Updates Top

bartblast
After building Hologram and sharing updates across various places, I’ve realized there’s a lot happening that doesn’t always make it to t...
New
kip
I’m a bit excited to announce that Localize and friends are now at release 1.0. Even though it’s a 1.0 release, it stands on 8 years of w...
New
nseaSeb
Just published search_ash 0.5.0 (with search_core 0.4.0) on Hex. What’s new: synonyms You can now declare a synonym dictionary per lang...
New
mudasobwa
After years of struggling I made StreamData dependency optional. Finitomata.ExUnit got testing primitives for Persistence. Full back co...
New
polvalente
We have released v0.13 of nx, exla and torchx, along with a recently released emlx v0.4. Nx This is where the bulk of the updates happen...
New
sullyMusty
ActiveMemory 0.8.0 is on Hex. It’s an in-memory store built on ETS and Mnesia: typed records you query by **any attribute**, not just a ...
New
bartblast
Hologram v0.11 is out! Two headline features this release. First, Elixir regexes now run in the browser. They were server-only until now,...
New

Other Trending Topics Top

JesseHerrick
Hey, I’m Jesse and I’m the main contributor behind Dexter, a full-featured, lightning-fast Elixir LSP optimized for large codebases. It s...
New
jimsynz
Beam Bots (or just BB for short) is a framework for building fault-tolerant robotics applications in Elixir using familiar OTP patterns. ...
New
Damirados
Hello everyone. After busy few months I am happy to announce v0.1.0 of Emerge & Solve. They are GUI (Emerge) and State management (S...
New
ausimian
Emily is an Elixir library that runs Nx computations on Apple’s MLX. Install it as the default Nx backend and Nx, defn, Axon, Nx.Serving,...
New
type1fool
I just stumbled on a newly redesigned elixir-lang.org. :tada: It looks like @Software_Mansion did the work, and I think it is generally a...
New
akoutmos
@hugobarauna and I (Alex Koutmos) have been hard at work on writing a book on Nerves that takes you from simply blinking LEDs to building...
New

We're in Beta

About us Mission Statement