MrMasterbay 97bed19987 security(status): escape unparseable timestamps in status-page fmtTime (CWE-79)
fmtTime() returned the raw input string when a value did not parse as a
date, and that string is concatenated into the incident HTML. A malicious
admin could store markup (e.g. a <link>/<img> to an attacker HTTPS
resource) in started_at/resolved_at and force viewers to load it. Route
the fallback through the existing escapeHtml helper; valid dates still
render via toLocaleString. (Aikido low #338694499)
2026-07-21 08:10:10 +02:00
..