This project is archived and is in readonly mode.

#6025 ✓stale
Tohru Hashimoto

render :json don't escape htmlentities.

Reported by Tohru Hashimoto | November 21st, 2010 @ 07:00 AM

XSS happend by IE6 and IE7.


class JsonController < ApplicationController
  def index
    xss = "<script>alert('hoge')</script>"
    render :json => {:a => xss }


RenderJsonXss::Application.routes.draw do
  root :to => 'json#index'

and access to http://localhost:3000/.html with IE6 or IE7.


I think render :json should escape htmlentities.

Comments and changes to this ticket

  • Andrés Mejía

    Andrés Mejía November 21st, 2010 @ 03:04 PM

    -1 on this.

    Why would you directly access an action that renders JSON in the first place?

    I don't really see how could this be used for an XSS attack. Mind explaining?

    And if you really want to escape the content, you can use:

        render :json => {:a => CGI::escape(xss) }

    But I don't see any reason for this to be the default behavior.

  • rails

    rails February 22nd, 2011 @ 12:00 AM

    • State changed from “new” to “open”

    This issue has been automatically marked as stale because it has not been commented on for at least three months.

    The resources of the Rails core team are limited, and so we are asking for your help. If you can still reproduce this error on the 3-0-stable branch or on master, please reply with all of the information you have about it and add "[state:open]" to your comment. This will reopen the ticket for review. Likewise, if you feel that this is a very important feature for Rails to include, please reply with your explanation so we can consider it.

    Thank you for all your contributions, and we hope you will understand this step to focus our efforts where they are most helpful.

  • rails

    rails February 22nd, 2011 @ 12:00 AM

    • State changed from “open” to “stale”

Create your profile

Help contribute to this project by taking a few moments to create your personal profile. Create your profile »

<h2 style="font-size: 14px">Tickets have moved to Github</h2>

The new ticket tracker is available at <a href=""></a>

People watching this ticket