wiki-viewer
Warn
Audited by Socket on Sep 14, 2026
1 alert found:
AnomalyAnomalyscripts/render.js
LOWAnomalyLOW
scripts/render.js
No clear evidence of intentional malware behavior (no network/exfiltration/backdoor mechanics shown). The primary security issue is stored XSS: the client-side code injects page.html directly into the DOM using innerHTML without sanitization in this fragment. If page.html can contain attacker-controlled HTML/JS (e.g., from untrusted wiki authors or unsafe upstream conversion), opening the generated viewer.html and navigating to a page can execute arbitrary script in the viewer context. Additional lower-impact risks include clipboard manipulation and potential output-path misuse if CLI/path inputs are not controlled.
Confidence: 62%Severity: 60%
Audit Metadata