Skip to content

Potential fix for code scanning alert no. 3: Incomplete multi-character sanitization - #3

Merged
PRATHAM777P merged 1 commit into
mainfrom
alert-autofix-3
Apr 27, 2026
Merged

PRATHAM777P merged 1 commit into
mainfrom
alert-autofix-3

Conversation

@PRATHAM777P

Copy link
Copy Markdown
Owner

Potential fix for https://github.com/PRATHAM777P/AlphaMind/security/code-scanning/3

Use iterative replacement for the multi-character block-tag removals (script, style, noscript) so replacements are applied until the string stabilizes.

Best minimal fix (without changing intended functionality):

  • In src/tools/fetch/web-fetch-utils.ts, around lines 38–41 in htmlToMarkdown, replace the chained single-pass .replace(...) calls with a small do...while loop that repeatedly removes those blocks until no further changes occur.
  • Keep all existing behavior afterward (anchor/header/list conversions, stripTags, whitespace normalization) unchanged.

No new imports or dependencies are required.

Suggested fixes powered by Copilot Autofix. Review carefully before merging.

…er sanitization

Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
@PRATHAM777P
PRATHAM777P marked this pull request as ready for review April 27, 2026 18:15
Comment on lines +42 to +44
text = text
.replace(/<script[\s\S]*?<\/script>/gi, "")
.replace(/<style[\s\S]*?<\/style>/gi, "")
Comment on lines +42 to +43
text = text
.replace(/<script[\s\S]*?<\/script>/gi, "")
do {
previous = text;
text = text
.replace(/<script[\s\S]*?<\/script>/gi, "")
@PRATHAM777P
PRATHAM777P merged commit 8e8bc9a into main Apr 27, 2026
1 of 2 checks passed
@PRATHAM777P
PRATHAM777P deleted the alert-autofix-3 branch April 27, 2026 18:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants