Screen picker: remove nodeIntegration and script-injected data #7

Closed
opened 2026-10-03 09:24:07 -04:00 by adam · 1 comment
Owner

Problem: The picker window runs with nodeIntegration: true, contextIsolation: false, and source names (window titles) are interpolated into a <script> via JSON.stringify, which does not escape </script>.

Impact: Any window title — e.g. a browser tab whose page sets <title></script><script>require('child_process')… — breaks out of the script block when the picker opens → arbitrary code execution.

Fix:

  • contextIsolation: true, nodeIntegration: false, small preload exposing select/cancel/listAudio.
  • Pass sources over IPC (or loadFile + postMessage) instead of string-templating into the HTML.
  • Delete dead showAudioOnlyPicker (also builds innerHTML from app names).
  • Remove ipcMain.once('picker-select'|'picker-cancel') leftovers when the window closes (they accumulate per open).

Where: src/picker.js

**Problem:** The picker window runs with `nodeIntegration: true, contextIsolation: false`, and source names (window titles) are interpolated into a `<script>` via `JSON.stringify`, which does not escape `</script>`. **Impact:** Any window title — e.g. a browser tab whose page sets `<title></script><script>require('child_process')…` — breaks out of the script block when the picker opens → arbitrary code execution. **Fix:** - `contextIsolation: true`, `nodeIntegration: false`, small preload exposing `select/cancel/listAudio`. - Pass sources over IPC (or `loadFile` + `postMessage`) instead of string-templating into the HTML. - Delete dead `showAudioOnlyPicker` (also builds `innerHTML` from app names). - Remove `ipcMain.once('picker-select'|'picker-cancel')` leftovers when the window closes (they accumulate per open). **Where:** `src/picker.js`
Author
Owner

Fixed by #11 (#11)

Fixed by #11 (https://git.galactica.host/adam/sunburn-desktop/pulls/11)
adam closed this issue 2026-10-03 11:58:44 -04:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
adam/sunburn-desktop#7
No description provided.