Hunting Server Side Rendering And Svg Image Abuse

Hunt abuse of server-side renderers of user-supplied markup, such as headless-browser PDF or screenshot generation, SVG rasterization, thumbnailers, and chart or document renderers, where the renderer fetches remote or local resources, follows redirects, executes embedded script, or reads local files while producing output. Use when untrusted HTML, SVG, or a URL is handed to a rendering component server-side. Covers server-side request forgery including to cloud metadata, local file disclosure through file schemes or external entities, blind out-of-band interaction, and script execution inside the generated document. The untrusted markup or URL is the source, the resolving renderer is the sink, and the fetch, file read, or script execution it performs is the bug.

UnboundCompute Updated

File contents

UnboundCompute/security-agent-skills/tree/main/skills/hunting-server-side-rendering-and-svg-image-abuse commit eddb768387

Frequently asked questions

npx skillmds@latest add unboundcompute/hunting-server-side-rendering-and-svg-image-abuse