sanitize iframe bodyClasses and bodyStyles in getIframeHtml
details
- Finding IDs
- F-PROTON-WEBCL-001
- Status
- fixed in public source; rollout not reverified
- Reported via
- security contact
- Note
- reviewed source escapes bodyClasses and bodyStyles with escapeHTMLAttribute before HTML attribute insertion. the previously cited c65861cab0a3 commit changes VPN retention-policy settings, not this renderer. prior fix-date, release and production-rollout claims are not supported by that commit and are withdrawn pending separate evidence.
F-PROTON-WEBCL-001: Code / markup injection. Unescaped class/style attribute values enter generated iframe HTML. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-PROTON-WEBCL-001
Security area (1seal assessment): Semantics. The inspected mail renderer escapes class/style attribute data before HTML insertion. This supports a data-to-markup boundary classification, not the previously recorded fix date or production rollout. Reviewed 21 Sep 2026.