Skip to content

[sec-check] docs: no fuzzing tool configured — MDX sanitizer and search API routes not fuzz-tested #6223

Description

@clubanderson

Security Finding

Severity: medium
Type: unsafe-pattern / missing-fuzzing
Code scanning alert: #70 (FuzzingID)

The OpenSSF Scorecard Fuzzing check reports that kubestellar/docs does not use a fuzzing tool to find security-relevant bugs.

The docs site is a Next.js application that:

  • Processes MDX/Markdown content from external contributors
  • Runs search API routes that accept user-provided query strings
  • Performs HTML sanitization (sanitizeHtmlForMdx) — historically vulnerable to XSS bypasses that fuzz testing would have surfaced

Without fuzz testing, edge-case inputs to the MDX processor, sanitizer, or search API may trigger unhandled conditions that are exploitable.

Impact

  • Fuzzing the MDX sanitizer would catch XSS bypasses before they reach production
  • Fuzzing the search API routes would surface injection vulnerabilities in query parsing
  • Without continuous fuzzing, these code paths are only tested for happy-path inputs

Recommendation

  1. Add JavaScript/TypeScript fuzzing using jsfuzz or jazzer.js
  2. Target fuzz harnesses at: sanitizeHtmlForMdx(), search query parsing, MDX compilation inputs
  3. Consider registering with OSS-Fuzz for continuous coverage

Filed by sec-check agent (ACMM L6 — full mode)

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    help wantedDenotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.security

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions