fix: escape fallback raw-content ancestor tags across foreign content namespaces - #36
Merged
alan-agius4 merged 1 commit intoAug 4, 2026
Conversation
alan-agius4
force-pushed
the
fix/noscript-foreign-content-escape
branch
from
August 3, 2026 13:08
a8cd644 to
86aad57
Compare
JeanMeche
reviewed
Aug 4, 2026
JeanMeche
approved these changes
Aug 4, 2026
… namespaces Escape ancestor fallback raw-content element closing tags (e.g., </noscript>) when nested inside SVG or MathML foreign content elements (e.g., <foreignObject>, <svg>, <math>, <mtext>). Previously, fallbackRawContentTags() stopped traversing ancestors when it encountered an element outside the HTML namespace, causing it to miss enclosing fallback raw-content tags and leave their closing tags unescaped. Closes angular/angular#70055
alan-agius4
force-pushed
the
fix/noscript-foreign-content-escape
branch
from
August 4, 2026 08:17
86aad57 to
5d2158c
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Escape ancestor fallback raw-content element closing tags (e.g.,
</noscript>) when nested inside SVG or MathML foreign content elements (e.g.,<foreignObject>,<svg>,<math>,<mtext>).Previously,
fallbackRawContentTags()inlib/NodeUtils.jsstopped traversing ancestors when it encountered an element outside the HTML namespace (node.namespaceURI === NAMESPACE.HTML). When a fallback raw-content element like<noscript>,<iframe>,<noembed>, or<noframes>contained SVG or MathML foreign content,fallbackRawContentTags()returned an empty array, causing matching closing tags inside comments and non-fallback raw-text elements (<xmp>,<style>, etc.) to be emitted unescaped.Solution
while (node?.nodeType === 1 /*ELEMENT_NODE*/)).if (node.namespaceURI === NAMESPACE.HTML && hasRawContentFallback[node.tagName])).test/xss.jscovering foreign content (svg > foreignObjectandmath > mtext) across all fallback raw-content tags.Closes angular/angular#70055