From 46bfe06e8aa4839ca5bca5a4b66cd05ce0b9ee0a Mon Sep 17 00:00:00 2001 From: Shota FUJI Date: Sun, 16 Aug 2026 11:31:48 +0900 Subject: [PATCH] Fix raw blob page renders HTML file https://tangled.org/pocka.jp/legit/issues/30 When an attacker has commit access to a repository or let the site admin add attacker controlled repository to repository list, they can serve arbitrary static HTML file under the legit's domain. For example, an attacker can distribute a page looks like legit's interface (phishing) and present a link for downloading a malware. Risk is low, considering this software is primarily used by individuals for their own softwares and softwares they trusted. The "why" is due to bad design of "net/http" package. The header manipulations after "WriteHeader" or "Write" will be ignored. This is stated in the docs but really easy to (mis)use, because there're no mechanism or expression to tell this. This patch also changes "Content-Type" of images and videos. Browsers render these fine as they sniff the content type and _correct_ the "text/plain" to "image/png" or whatever they sniffed. --- pages/repo/blob.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pages/repo/blob.go b/pages/repo/blob.go index ed7faa4..520aee3 100644 --- a/pages/repo/blob.go +++ b/pages/repo/blob.go @@ -62,8 +62,8 @@ func (repo *Repo) blob(pathRemainings string, w http.ResponseWriter, r *http.Req return } - w.WriteHeader(http.StatusOK) w.Header().Set("Content-Type", "text/plain") + w.WriteHeader(http.StatusOK) if _, err := io.Copy(w, reader); err != nil { log.Printf("io copy failed: %s", err) -- 2.51.2