Skip to content

Strip bare control characters from CSP report terminal output - #1405

Merged
richard-to merged 1 commit into
mainfrom
claude/elegant-hypatia-wl74fa
Sep 26, 2026
Merged

richard-to merged 1 commit into
mainfrom
claude/elegant-hypatia-wl74fa

Conversation

@richard-to

Copy link
Copy Markdown
Collaborator

_sanitize_terminal() only removed ESC-prefixed ANSI sequences. Bare control characters in the unauthenticated /__csp__ report fields were still printed to the operator's terminal, so an attacker could overwrite or forge log lines. This covers:

  • C0 controls such as CR, LF, BS and BEL
  • DEL
  • C1 controls, e.g. 0x9B (8-bit CSI)
  • a stray ESC

Changes

  • After the ANSI escape pass, _sanitize_terminal() now also strips all remaining C0, DEL and C1 control characters, plus Unicode bidi override characters (U+200E/F, U+202A–202E, U+2066–2069). Ordinary non-ASCII text is kept.
  • The regex is a raw string, so ruff format can't rewrite the escapes into invisible literal characters in the source.

Tests

  • New unit tests cover each control character, the bidi overrides and non-ASCII text being kept.
  • A new end-to-end /__csp__ test uses CR and LF injection payloads.
  • The new tests fail on the old code. All 62 tests in mesop/server pass, and ruff check / ruff format --check (v0.5.4) pass.

Reported by zx (@manus-pi).

🤖 Generated with Claude Code

https://claude.ai/code/session_019b8mWRK1bS7PUszC6SQKGB


Generated by Claude Code

_sanitize_terminal() only removed ESC-prefixed ANSI sequences, so bare
C0 controls (CR, LF, BS, BEL, ...), DEL, C1 controls (e.g. 0x9B 8-bit
CSI) and a stray ESC in unauthenticated /__csp__ report fields reached
the operator's terminal, allowing log lines to be overwritten or forged.

Strip all remaining control characters and Unicode bidi overrides after
the ANSI escape pass.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019b8mWRK1bS7PUszC6SQKGB
@richard-to
richard-to merged commit a073db8 into main Sep 26, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants