FixVibe

// نشط / تسليط الضوء

XSS قائم على DOM عبر شظية URL

تطبيقات SPA الحديثة تقرأ location.hash وتكتبه في DOM — وحمولات المهاجم ترافقها.

What it is

DOM-based XSS is XSS where the server is innocent. The bug lives entirely in your client-side JavaScript, and your server logs will never show a trace of the attack — the URL fragment after `#` never reaches the server. That makes it the form of XSS most likely to slip through both WAF and SOC. SPA frameworks have made it more common in production, not less: every router that reads location for state, every analytics tag that grabs query parameters, every 'remember the user's input' pattern that stores partial state in the URL is a candidate. The classic Reflected XSS that lived in server-rendered HTML has migrated client-side.

How it happens

DOM XSS appears when client-side JavaScript moves URL or state data into the page without safe encoding. The server may be clean while the shipped frontend creates the execution path.

What an attacker gets

Same as classical XSS — full JavaScript execution context inside your origin, with access to cookies (unless HttpOnly), localStorage, the DOM, and any auth tokens visible to JS. Account takeover via session theft, action hijack on behalf of the user, or a phishing overlay convincing enough that the user re-enters credentials inside the legitimate origin.

// what fixvibe reports

What FixVibe reports

Runs in active scans of a domain you have verified you own, on Hobby and above. Each finding shows the affected URL or host, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Don't pass URL data to dangerous sinks. Use `textContent` for inserting text into the DOM. For frameworks, lean on the safe-by-default rendering — React's children, Vue's `{{ }}`, Angular's interpolation — and audit every `dangerouslySetInnerHTML`, `v-html`, and `[innerHTML]` for whether the input is trusted. When you genuinely need to render user-supplied HTML, sanitize through DOMPurify with a strict allowlist; never write your own sanitizer. Avoid `eval`, `setTimeout(string)`, `Function(string)`, `setInterval(string)` — anywhere a string-as-code is accepted. Apply a strict Content Security Policy without `unsafe-eval` and with `script-src 'self' 'strict-dynamic' 'nonce-…'` so even successful injection can't execute. As a sanity check, search your codebase for assignments to `innerHTML` and reads of `location.hash` — every match is a code path to review.

// شغّله على تطبيقك

واصل الإطلاق بينما يراقب FixVibe المخاطر.

Verify you own the domain, then run active checks alongside the passive ones.

الفحوصات النشطة
138
اختبار في هذه الفئة
وحدة
58
فحص الفحوصات النشطة مخصص
verified domains
130+
active checks after verification
Verify your domain →

// فحوصات حديثة · إصلاحات عملية · أطلق بثقة

XSS قائم على DOM عبر شظية URL: what it is and how to fix it · FixVibe