Skip to content

Commit e50f504

Browse files
arturovtpkozlowski-opensource
authored andcommitted
fix(zone.js): validate __Zone_symbol_prefix to prevent DOM clobbering attacks
Previously, `__Zone_symbol_prefix` was read directly from `globalThis` without validating its type: const symbolPrefix = global['__Zone_symbol_prefix'] || '__zone_symbol__'; This made it possible for DOM clobbering to interfere with Zone’s internal symbol handling. If an attacker injected a DOM element with the same name (for example via a form field or anchor ID), `global['__Zone_symbol_prefix']` could resolve to a DOM element instead of a string. Because DOM elements are truthy, the fallback would not be used, and Zone would construct invalid internal keys (e.g. “[object HTMLFormElement]...”), breaking patching and lookup logic in subtle ways. This prevents DOM clobbering from influencing Zone’s internal symbol generation and keeps the patching system stable even in the presence of malicious or unexpected global values.
1 parent d109bf9 commit e50f504

1 file changed

Lines changed: 5 additions & 3 deletions

File tree

‎packages/zone.js/lib/zone-impl.ts‎

Lines changed: 5 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -762,10 +762,12 @@ export type AmbientZone = Zone;
762762

763763
const global = globalThis as any;
764764

765-
// __Zone_symbol_prefix global can be used to override the default zone
766-
// symbol prefix with a custom one if needed.
765+
// __Zone_symbol_prefix can be set globally to override the default zone symbol prefix.
767766
export function __symbol__(name: string) {
768-
const symbolPrefix = global['__Zone_symbol_prefix'] || '__zone_symbol__';
767+
const rawPrefix = global['__Zone_symbol_prefix'];
768+
// Guard against DOM clobbering: an attacker can set __Zone_symbol_prefix to an HTMLElement
769+
// via e.g. <input name="__Zone_symbol_prefix">, so we only trust it if it's actually a string.
770+
const symbolPrefix = typeof rawPrefix === 'string' ? rawPrefix : '__zone_symbol__';
769771
return symbolPrefix + name;
770772
}
771773

0 commit comments

Comments
 (0)