Author: Andy Green Date: Sun Sep 06 08:40:57 2026 +0100 web: JSON-escape alang in builders message header, fixes F-005 The com.warmcat.sai.builders header interpolated pss->alang (the browser-controlled Accept-Language header captured at the ws upgrade) after lws_sql_purify(), which only doubles single quotes and passes double quotes, braces and backslashes through untouched -- so an Accept-Language value like x"}INJECTED could add attacker-chosen JSON structure to the message the browser parses. The overview path already escapes the same field correctly with lws_json_purify(); use it here too. diff --git a/src/web/w-ws-browser.c b/src/web/w-ws-browser.c index fdcc16b..0941c6b 100644 --- a/src/web/w-ws-browser.c +++ b/src/web/w-ws-browser.c @@ -2067,7 +2067,8 @@ saiw_browser_broadcast_queue_builders(struct vhd *vhd, struct pss *pss) "{\"schema\":\"com.warmcat.sai.builders\"," " \"alang\":\"%s\"," " \"builders\":[", - lws_sql_purify(esc, pss->alang, sizeof(esc) - 1)); + lws_json_purify(esc, pss->alang, sizeof(esc) - 1, + NULL)); if (sai_dyn_buf_append(&d, buf, (size_t)n)) { free(d.buf); return 1;