From 2d748e4ac1724873b7ce40b9a293b7d2fa20d83b Mon Sep 17 00:00:00 2001 From: Vincent Koc Date: Thu, 30 Apr 2026 00:37:05 -0700 Subject: [PATCH] fix(security): sanitize QQBot debug log values Sanitizes QQBot debug log values to remediate CodeQL alert 230. --- CHANGELOG.md | 1 + extensions/qqbot/src/engine/utils/log.test.ts | 28 +++++++++++++++ extensions/qqbot/src/engine/utils/log.ts | 35 +++++++++++++++++-- 3 files changed, 61 insertions(+), 3 deletions(-) create mode 100644 extensions/qqbot/src/engine/utils/log.test.ts diff --git a/CHANGELOG.md b/CHANGELOG.md index 5c359b507f8..89e4db7d102 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -42,6 +42,7 @@ Docs: https://docs.openclaw.ai - Security/outbound: strip re-formed HTML tags during plain-text sanitization so nested tag fragments cannot leave a CodeQL-detected `