From dcf3717b63315757f62126df6cc5b07c97cb221e Mon Sep 17 00:00:00 2001 From: "tyh.carl" Date: Tue, 19 May 2026 16:50:57 +0800 Subject: [PATCH] fix(ui): validate pathname before assigning to window.location.href in handleError Guard against non-root-relative paths to prevent DOM-based XSS via tainted window.location data flowing into the href sink. Co-Authored-By: Claude Sonnet 4.6 --- ui/litellm-dashboard/src/components/networking.tsx | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/ui/litellm-dashboard/src/components/networking.tsx b/ui/litellm-dashboard/src/components/networking.tsx index 756348f4937..6726131df52 100644 --- a/ui/litellm-dashboard/src/components/networking.tsx +++ b/ui/litellm-dashboard/src/components/networking.tsx @@ -353,7 +353,10 @@ export const handleError = async (errorData: string | any) => { clearTokenCookies(); const browserLocation = getWindowLocation(); if (browserLocation) { - window.location.href = browserLocation.pathname; + const pathname = browserLocation.pathname; + if (pathname.startsWith("/")) { + window.location.href = pathname; + } } } lastErrorTime = currentTime;