Post-batch security review (2026-07-03), defense-in-depth. Not currently exploitable — the font picker only offers the 7 hardcoded FontRegistry CSS stacks, the whole declaration is wrapped in escapeAttr (a value can't break out of the style="…" attribute or inject a tag), and reply/forward reduces untrusted sender HTML to plaintext before it can reach RichStyle.FontFamily. This is insurance against those invariants changing.
Problem
RichTextHtml.inlineCss (~line 200) and baseCss (~line 29) interpolate the font-family value into the emitted HTML style attribute raw (no escaping of ;/:). If a non-registry value ever reached emit, the worst case is a sibling CSS-property injection inside the attribute.
Scope
On HTML emit, constrain the font-family value to the known-good FontRegistry stacks (whitelist) — or otherwise restrict it to a safe charset — dropping/defaulting anything unrecognized instead of emitting it raw.
Unit test: a RichStyle.FontFamily carrying an unexpected value (e.g. Arial; color:red) does not appear raw in the emitted HTML.
Files
richtext/RichTextHtml.kt; ui/compose/format/FontRegistry (source of the whitelist).
Notes
Defense-in-depth only — no behavior change for the built-in fonts. Origin: post-batch security review of PRs #194–#201.
## Origin
Post-batch security review (2026-07-03), defense-in-depth. **Not currently exploitable** — the font picker only offers the 7 hardcoded `FontRegistry` CSS stacks, the whole declaration is wrapped in `escapeAttr` (a value can't break out of the `style="…"` attribute or inject a tag), and reply/forward reduces untrusted sender HTML to plaintext before it can reach `RichStyle.FontFamily`. This is insurance against those invariants changing.
## Problem
`RichTextHtml.inlineCss` (~line 200) and `baseCss` (~line 29) interpolate the `font-family` value into the emitted HTML `style` attribute raw (no escaping of `;`/`:`). If a non-registry value ever reached emit, the worst case is a sibling CSS-property injection inside the attribute.
## Scope
- On HTML emit, constrain the `font-family` value to the known-good `FontRegistry` stacks (whitelist) — or otherwise restrict it to a safe charset — dropping/defaulting anything unrecognized instead of emitting it raw.
- Unit test: a `RichStyle.FontFamily` carrying an unexpected value (e.g. `Arial; color:red`) does not appear raw in the emitted HTML.
## Files
`richtext/RichTextHtml.kt`; `ui/compose/format/` `FontRegistry` (source of the whitelist).
## Notes
Defense-in-depth only — no behavior change for the built-in fonts. Origin: post-batch security review of PRs #194–#201.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Origin
Post-batch security review (2026-07-03), defense-in-depth. Not currently exploitable — the font picker only offers the 7 hardcoded
FontRegistryCSS stacks, the whole declaration is wrapped inescapeAttr(a value can't break out of thestyle="…"attribute or inject a tag), and reply/forward reduces untrusted sender HTML to plaintext before it can reachRichStyle.FontFamily. This is insurance against those invariants changing.Problem
RichTextHtml.inlineCss(~line 200) andbaseCss(~line 29) interpolate thefont-familyvalue into the emitted HTMLstyleattribute raw (no escaping of;/:). If a non-registry value ever reached emit, the worst case is a sibling CSS-property injection inside the attribute.Scope
font-familyvalue to the known-goodFontRegistrystacks (whitelist) — or otherwise restrict it to a safe charset — dropping/defaulting anything unrecognized instead of emitting it raw.RichStyle.FontFamilycarrying an unexpected value (e.g.Arial; color:red) does not appear raw in the emitted HTML.Files
richtext/RichTextHtml.kt;ui/compose/format/FontRegistry(source of the whitelist).Notes
Defense-in-depth only — no behavior change for the built-in fonts. Origin: post-batch security review of PRs #194–#201.