Discuss Scratch

mali3000
Scratcher
1000+ posts

Custom project page colors/styles in ordinary scratch (plus more things)

Digitat321 wrote:

BobaFatL wrote:

ChristianScratcher1 wrote:

nembence wrote:

https://github.com/scratchfoundation/scratch-editor/pull/567
Can you quote the text on there? Github is blocked rn
snip
aw so they probably fixing the CSS exploit.
it still works right now but they will eventually
STebBerry
Scratcher
100+ posts

Custom project page colors/styles in ordinary scratch (plus more things)

i think they're trying to fix it, but at the moment it's not patched. my chatroom still has custom styling
ScodexPerson
Scratcher
1000+ posts

Custom project page colors/styles in ordinary scratch (plus more things)

Proof from Paddle2See that they're fixing it(?): https://scratch.mit.edu/discuss/topic/883932/?page=1#post-9177434

Paddle2See wrote:

Thanks - it's a known issue with CSS. I don't have an estimate on when it will be fixed but I believe it's harmless.

Last edited by ScodexPerson (May 15, 2026 16:45:28)

fortyonegames
Scratcher
100+ posts

Custom project page colors/styles in ordinary scratch (plus more things)

ScodexPerson wrote:

Proof from Paddle2See that they're fixing it(?): https://scratch.mit.edu/discuss/topic/883932/?page=1#post-9177434

Paddle2See wrote:

Thanks - it's a known issue with CSS. I don't have an estimate on when it will be fixed but I believe it's harmless.
this is why paddle2see is best scratch team member

Last edited by fortyonegames (May 15, 2026 17:53:08)

fortyonegames
Scratcher
100+ posts

Custom project page colors/styles in ordinary scratch (plus more things)

just found another scratch breaking bug

blessingj100
Scratcher
1000+ posts

Custom project page colors/styles in ordinary scratch (plus more things)

fortyonegames wrote:

just found another scratch breaking bug
Ok… What is it?
fortyonegames
Scratcher
100+ posts

Custom project page colors/styles in ordinary scratch (plus more things)

blessingj100 wrote:

fortyonegames wrote:

just found another scratch breaking bug
Ok… What is it?

im reporting it to the ST but it involves injecting XML into a certain part of the project
JamesTheScratcherBoy
Scratcher
100+ posts

Custom project page colors/styles in ordinary scratch (plus more things)

THE TUTORIAL GOT TAKEN DOWN
blessingj100
Scratcher
1000+ posts

Custom project page colors/styles in ordinary scratch (plus more things)

JamesTheScratcherBoy wrote:

THE TUTORIAL GOT TAKEN DOWN
Yeah, that was a while ago, it got re-uploaded with a new link I think a month or so ago: https://scratch.mit.edu/projects/1311303013/
fortyonegames
Scratcher
100+ posts

Custom project page colors/styles in ordinary scratch (plus more things)

bump
Digitat321
Scratcher
25 posts

Custom project page colors/styles in ordinary scratch (plus more things)

whitnlan000 wrote:

Digitat321 wrote:

BobaFatL wrote:

ChristianScratcher1 wrote:

nembence wrote:

https://github.com/scratchfoundation/scratch-editor/pull/567
Can you quote the text on there? Github is blocked rn
Resolves

https://scratchfoundation.atlassian.net/browse/UEPR-231

Proposed Changes
  • Load SVGs into a sandboxed iframe for measurement vs directly into the DOM.
  • Introduce a new function for removing malicious content from SVGs - canonicalizeSvgText
  • TODO: Route all svg loads through canonicalizeSvgText - at the point of loadVector_
Reason for Changes

Currently we attempt to sanitize SVGs, but the approach is piecemeal. The biggest security issue in the current state is that we load SVGs directly into the DOM, which is an inherently unsafe operation.

Test Coverage

Added tests for sandboxing, canonicalization and measuring SVGs in a sandboxed environment.
aw so they probably fixing the CSS exploit.

Guess not. The ACE is gone.
Its like they always fix the issue with the SVG sanitisation without fixing the CSS exploit lol, (correct me if im wrong but this has happened before?) or something similar with ace or XSS
blessingj100
Scratcher
1000+ posts

Custom project page colors/styles in ordinary scratch (plus more things)

Digitat321 wrote:

Its like they always fix the issue with the SVG sanitisation without fixing the CSS exploit lol, (correct me if im wrong but this has happened before?) or something similar with ace or XSS
Yeah, well, that could come to an end. Along with fixing the XSS glitch, the Github pulls to fix it and ones related to the SVG sanitizer said that there was going to be an SVG sandbox to stop it from leaking out, and when it comes out in full, it could put an end to the majority of SVG exploits.
fortyonegames
Scratcher
100+ posts

Custom project page colors/styles in ordinary scratch (plus more things)

Bump
fortyonegames
Scratcher
100+ posts

Custom project page colors/styles in ordinary scratch (plus more things)

Bump
Legon974
Scratcher
500+ posts

Custom project page colors/styles in ordinary scratch (plus more things)

i emailed the Scratch Team and uuuuuh they said is fixed
fortyonegames
Scratcher
100+ posts

Custom project page colors/styles in ordinary scratch (plus more things)

Legon974 wrote:

i emailed the Scratch Team and uuuuuh they said is fixed
they fixed the security issue but the styling is the same
blessingj100
Scratcher
1000+ posts

Custom project page colors/styles in ordinary scratch (plus more things)

fortyonegames wrote:

Legon974 wrote:

i emailed the Scratch Team and uuuuuh they said is fixed
they fixed the security issue but the styling is the same
I can confirm, the custom styling on my test project remains unchanged.
my_c00l_games
Scratcher
100+ posts

Custom project page colors/styles in ordinary scratch (plus more things)

blessingj100 wrote:

fortyonegames wrote:

Legon974 wrote:

i emailed the Scratch Team and uuuuuh they said is fixed
they fixed the security issue but the styling is the same
I can confirm, the custom styling on my test project remains unchanged.
Isn't that good?
medians
Scratcher
1000+ posts

Custom project page colors/styles in ordinary scratch (plus more things)

Legon974 wrote:

i emailed the Scratch Team and uuuuuh they said is fixed
Noooo
I wonder if someone added 2.0 CSS LOL

Last edited by medians (May 22, 2026 15:33:45)

3pinkdragon
Scratcher
5 posts

Custom project page colors/styles in ordinary scratch (plus more things)

Bump

Powered by DjangoBB