Skip to main content

AGENTFORCE-VF-01: Visualforce XSS via escape=false

๐Ÿšจ Critical ยท XSS

Detects Visualforce components with escape="false", which disables auto-escaping and enables XSS.

Detailsโ€‹

FieldValue
Rule IDAGENTFORCE-VF-01
SeverityCritical
CategoryXSS

Remediationโ€‹

Remove escape="false" or ensure the value is strictly sanitized server-side. Prefer apex:outputText with default escaping.

See Alsoโ€‹