SiteShadow
Back to vulnerability library
Detected byCWE-aware static analysis

CWE-83 Cross-Site Scripting in Attributes

Coverage: 3 rules in the SiteShadow rule registry target this CWE (registry v2.0.0). Regex 3 Also: Taint and heuristic analyzers may also detect related flows (see coverage for the authoritative list) Registry tagging shows intent, for sample-level behaviour and benchmarked gaps see known gaps.

What this means

SiteShadow flagged untrusted input flowing into HTML attributes or event handler contexts (e.g., href=, src=, on*=). Attribute contexts have different escaping rules than plain text.

Why it matters

Attribute injection can execute scripts or bypass sanitization.

Safer examples

1) Don't construct attributes from untrusted strings

Prefer framework bindings that correctly encode attributes.

2) Allowlist URL schemes and hosts

const u = new URL(inputUrl, "https://example.com");
if (!["https:"].includes(u.protocol)) throw new Error("Invalid scheme");

3) Avoid inline event handlers entirely

Never build onclick="..." from user input. Use addEventListener with safe data handling.

How SiteShadow detects it (high level)

References

---

← Back to Vulnerability Library

Catch this in your code with SiteShadow.

Every released SiteShadow scanner is free, including full project analysis, reports, patterns, dashboard access, and configured organization SSO.