AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Moderate 66 Monero

qml: escape untrusted text in remaining RichText views

Public commit record

What the developer wrote

Authored by Thomas

85/100 · Strong
qml: escape untrusted text in remaining RichText views

Extends the escaping from commit 23ec5eb6 to the RichText sinks it did
not cover: the transaction note in the tx details popup (History), the
wallet name and account label in the send confirmation
(TxConfirmationDialog), the address label on the merchant page
(Merchant), and the wallet path on the info page (SettingsInfo). These
were interpolated unescaped, so a value containing markup is rendered as
rich text.

The transaction note is the notable case: it can be set from a payment
request's tx_description, so it is attacker influenced.

Escape these fields with Utils.htmlEscape. Set the send confirmation
From field to Text.RichText explicitly so the escaped entities decode in
both of its branches; the single-account branch contains no tag and
would otherwise render as plain text and show the raw entity.
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Explains rationale or failure mode
The short version

What changed, and why it matters

This commit fixes a bug where user-controlled text was being displayed as rich text in several places in the Monero wallet app. Rich text can include hidden instructions, fake links, or misleading formatting. The most important case is the transaction note, which can be supplied by someone sending you a payment request, so an attacker could potentially use it to trick you. The fix escapes that text so it is shown as plain characters rather than interpreted as formatting or code.

Recommended action

Review the commit for completeness and confirm no other RichText sinks interpolate untrusted data. Consider auditing all QML Text.RichText usages in the codebase for similar escaping gaps. No immediate user action is required beyond updating to the patched version.

Security signals we found

01

RichText injection / UI spoofing via unescaped attacker-influenced strings

02

Cross-branch rendering inconsistency fixed by explicit textFormat

03

Follow-up to prior escaping fix (commit 23ec5eb6), indicating a class of similar sinks

Risk score

Why this scored 66/100

Our methodology →
Potential impact 18/30
Exploitability 16/25
Stealth signal 10/15
Affected reach 10/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.