No innerHTML for user input
Detect element.innerHTML = <expression> patterns in JavaScript / TypeScript /
HTML files. innerHTML assignment of untrusted input is the most common XSS
vector. Use textContent for text, or a sanitized DOM API for HTML fragments.
Detection#
Regex: \.innerHTML\s*=\s*[^"' + “" + ](i.e., innerHTML assignment of anything that isn't a string literal). Conservative: false positives onel.innerHTML = ‘’`
are acceptable.
Override#
Per-file: <!-- appframes:disable security/no-innerHTML-user-input --> at the
top of the file (after the doctype if HTML). Per-line: // appframes:disable-next-line.
WARN lets the push through and records the finding. Turn frames on per repo on the dashboard's Policy page - see choosing what the gate checks.
Source on GitHub Live demo How it works Questions: contact@nimblegate.com