Docs menu

No innerHTML for user input

WARN Frame security/no-innerHTML-user-input

Detect element.innerHTML = <expression> patterns in JavaScript / TypeScript / HTML files. innerHTML assignment of untrusted input is the most common XSS vector. Use textContent for text, or a sanitized DOM API for HTML fragments.

Detection#

Regex: \.innerHTML\s*=\s*[^"' + “" + ](i.e., innerHTML assignment of anything that isn't a string literal). Conservative: false positives onel.innerHTML = ‘’` are acceptable.

Override#

Per-file: <!-- appframes:disable security/no-innerHTML-user-input --> at the top of the file (after the doctype if HTML). Per-line: // appframes:disable-next-line.

WARN lets the push through and records the finding. Turn frames on per repo on the dashboard's Policy page - see choosing what the gate checks.

Source on GitHub Live demo How it works Questions: contact@nimblegate.com