🔒 Security fix
Upgrade to v6.6.1 if you process JUnit reports from untrusted sources, including fork pull requests.
This release fixes GHSA-448p-3p5j-c948: test and suite names could inject HTML or Markdown into Job Summaries and PR comments, allowing misleading content, links or images to appear in test reports. The issue affects versions through v6.6.0. Its assessed severity is low; the reported impact is content spoofing, not JavaScript execution.
The fix escapes report-derived text in detailed and flaky summaries, grouped suite headings, and check names and links when group_reports: false. It also handles line breaks that could allow Markdown injection.
Thank you to @f0909172434 for responsibly reporting this vulnerability.
📦 Dependencies
- Update
source-map-jsto patched version1.2.2(#1632). - Update
mikepenz/release-changelog-builder-actiontov6.4.0(#1631).
Contributors
@mikepenz, @renovate-mike[bot], and security reporter @f0909172434.