From 3275e878643e44a1b3816d861fae5f77b48108bc Mon Sep 17 00:00:00 2001 From: anupamme Date: Mon, 28 Sep 2026 12:53:09 +0000 Subject: [PATCH] fix: multi_agent.cwe-1321 security vulnerability Automated security fix generated by OrbisAI Security --- main/files.js | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/main/files.js b/main/files.js index e1025be7..d196476f 100644 --- a/main/files.js +++ b/main/files.js @@ -115,10 +115,20 @@ export function saveWorkspace(workspace) { } function validateBlocklyJson(json) { - // 1. Parse JSON safely + // 1. Parse JSON safely. Reject dangerous keys via a reviver so they are + // rejected as each one is parsed, before they can ever be attached to an + // object - closing the window between JSON.parse() and the post-parse + // dangerous-key check below. + function safeReviver(key, value) { + if (key === '__proto__' || key === 'constructor' || key === 'prototype') { + throw new Error(`Dangerous property found: ${key}`); + } + return value; + } + let data; try { - data = typeof json === 'string' ? JSON.parse(json) : json; + data = typeof json === 'string' ? JSON.parse(json, safeReviver) : json; } catch { throw new Error('Invalid JSON format'); }